FreshRSS

πŸ”’
☐ β˜† βœ‡ The Register - Security

French parliament says oui to AI surveillance for 2024 Paris Olympics

March 24th 2023 at 06:24

LibertΓ©, Γ©galitΓ©, reconnaissance faciale for all

Despite the opposition of 38 civil society groups, the French National Assembly has approved the use of algorithmic video surveillance during the 2024 Paris Olympics.…

☐ β˜† βœ‡ The Register - Security

Uncle Sam reveals it sent cyber-soldiers to Albania to hunt for Iranian threats

March 24th 2023 at 01:05

'Hunt forward' teams of this sort aid with defense and learn how attackers like Tehran operate

US Cyber Command operators have confirmed they carried out an online defensive mission in Albania, in response to last year's cyber attacks against the local government.…

☐ β˜† βœ‡ The Register - Security

Critical infrastructure gear is full of flaws, but hey, at least it's certified

March 23rd 2023 at 21:59

Security researchers find bugs, big and small, in every industrial box probed

Devices used in critical infrastructure are riddled with vulnerabilities that can cause denial of service, allow configuration manipulation, and achieve remote code execution, according to security researchers.…

☐ β˜† βœ‡ The Register - Security

Secure mail

March 23rd 2023 at 09:48

Protection from business email compromise

Webinar In the distant past, a master forger with a quill could fake a signature on the end of a letter but at least then you had time to consider the potential for fraud before any damage could be done. In the digital age of email, it's increasingly hard to spot a scam's threat to your security and react in time.…

☐ β˜† βœ‡ The Register - Security

Attackers hit Bitcoin ATMs to steal $1.5 million in crypto cash

March 23rd 2023 at 09:02

Terminal maker General Bytes shutters its cloud business after second breach in seven months

Unidentified miscreants have siphoned cryptocurrency valued at more than $1.5 million from Bitcoin ATMs by exploiting an unknown flaw in digicash delivery systems.…

☐ β˜† βœ‡ The Register - Security

Bogus ChatGPT extension steals Facebook cookies

March 23rd 2023 at 07:29

All aboard the chatbot hype train! Next stop: Fraud

Google has removed a ChatGPT extension from the Chrome store that steals Facebook session cookies – but not before more than 9,000 users installed the account-compromising bot.…

☐ β˜† βœ‡ The Register - Security

B-List celebs including Lindsay Lohan fined after crypto shill probe

March 23rd 2023 at 06:30

Didn't disclose payments as mastermind pumped up value of tokens with fake trades

Eight very B-list celebrities have agreed to cough up fines after being accused of shilling a cryptocurrency without disclosing they were paid to do so, while the chap who apparently paid them has been charged with fraud.…

☐ β˜† βœ‡ The Register - Security

South Korea fines McDonald's for data leak from raw SMB share

March 23rd 2023 at 02:29

British American Tobacco, Samsung, also burgered up their infosec

South Korea's Personal Information Protection Commission has fined McDonald's, British American Tobacco, and Samsung for privacy breaches.…

☐ β˜† βœ‡ The Register - Security

Cisco kindly reveals proof of concept attacks for flaws in rival Netgear's kit

March 22nd 2023 at 22:57

Maybe this is deserved given the problem's in a hidden telnet service

Public proof-of-concept exploits have landed for bugs in Netgear Orbi routers – including one critical command execution vulnerability. …

☐ β˜† βœ‡ The Register - Security

Journalist hurt by exploding USB bomb drive

March 22nd 2023 at 22:09

Now that's a flash bang

Police in Ecuador are investigating attacks on media organizations across the country after a journalist was injured by an exploding USB flash drive.…

☐ β˜† βœ‡ The Register - Security

German political parties accused of microtargeting voters on Facebook

March 22nd 2023 at 12:31

Country's super strong data rights under magnifying glass after half a dozen complaints filed

Remember the Who Targets Me browser extension from privacy activists at Noyb? The group yesterday filed explosive complaints based on log records from the extension that claim six of Germany's political parties broke European data law when they targeted voters on Facebook's adtech platform.…

☐ β˜† βœ‡ The Register - Security

Unknown actors deploy malware to steal data in occupied regions of Ukraine

March 22nd 2023 at 07:32

If this is Kyiv's work, Russia can Crimea river

A cyber espionage campaign targeting organizations in Russian-occupied regions of Ukraine is using novel malware to steal data, according to Russia-based infosec software vendor Kaspersky.…

☐ β˜† βœ‡ The Register - Security

India's absurd infosec reporting rules get just 15 followers

March 22nd 2023 at 03:30

CERT-In was told its six-hour notification requirement was a bad idea – now it knows just how bad

India's rules requiring local organizations to report infosec incidents within six hours of detection have been observed by a mere 15 entities/…

☐ β˜† βœ‡ The Register - Security

Xi, Putin declare intent to rule the world of AI, infosec

March 22nd 2023 at 01:58

'Technological sovereignty is the key to sustainability' states Russian despot

Russian president Vladimir Putin and his Chinese counterpart Xi Jinping have set themselves the goal of dominating the world of information technology.…

☐ β˜† βœ‡ The Register - Security

BreachForums shuts down ... but the RaidForums cybercrime universe will likely spawn a trilogy

March 22nd 2023 at 00:45

Admins decide reviving crime-mart is dangerous, hint at new chapter

BreachForums has reportedly shut down for good, just days after US authorities arrested the online criminal marketplace's alleged chief administrator.…

☐ β˜† βœ‡ The Register - Security

You just gonna take that AWS? Let Microsoft school your users on cloud security?

March 21st 2023 at 20:43

And Google Cloud is next

Microsoft has torn the wraps off its multi-cloud security benchmark (MCSB), which replaces the four-year-old Azure Security Benchmark. Crucially, as the name suggests, it now has usage and configuration guidance that reaches into rival environments.…

☐ β˜† βœ‡ The Register - Security

Ex-Meta security staffer accuses Greece of spying on her phone

March 21st 2023 at 08:31

Beware of Greeks bearing GIFs

Meta's former security policy manager, who split her time between the US and Greece, is reportedly suing the Hellenic national intelligence service for hacking her phone.…

☐ β˜† βœ‡ The Register - Security

Putin to staffers: Throw out your iPhones, or 'give it to the kids'

March 21st 2023 at 06:30

April Fools should use Russian or Chinese tech instead, Kremlin advises

Advisors and staff to Russia's maximum leader have been told to ditch their iPhones by the end of the month. Or, for those who don't want to throw their Apple devices in the bin, the other option is to "give it to the kids," according to a local Kommersant report.…

☐ β˜† βœ‡ The Register - Security

Google suspends top Chinese shopping app Pinduoduo

March 21st 2023 at 05:58

Alleges it’s infected with malware – but not the version in its own digital tat bazaar

Google has suspended Chinese shopping app Pinduoduo from its Play store because versions of the software found elsewhere have included malware.…

☐ β˜† βœ‡ The Register - Security

Australian FinTech takes itself offline to deal with cyber incident that caused data leak

March 21st 2023 at 03:58

Latitude blames a 'major vendor' for its woes. Is that a vendor? A cloud? Whoever they are, they're in trouble

Latitude Financial has blamed a supplier for leaking creds that caused vast PII leak Australian outfit Latitude Financial has taken itself offline, and even stopped serving customers, while it tries to clean up an attack on its systems.…

☐ β˜† βœ‡ The Register - Security

Ferrari in a spin as crims steal a car-load of customer data

March 21st 2023 at 01:45

Speeds away from the very suggestion it would ever pay a ransom

Italian automaker Ferrari has warned its well-heeled customers that their personal data may be at risk.…

☐ β˜† βœ‡ The Register - Security

Privacy fail: Pictures cropped, redacted by Google Pixel phones can be recovered

March 20th 2023 at 21:13

aCropalypse Now, starring any 2018-or-later device

Updated If you've owned a Google Pixel smartphone since the 3 series came out in 2018, bad news: any screenshot that you've cropped or redacted on your Pixel can be potentially restored without much fuss.…

☐ β˜† βœ‡ The Register - Security

BBC to staff: Uninstall TikTok from our corporate kit unless you can 'justify' having it

March 20th 2023 at 12:34

Those with 'sensitive' work-related information told to contact Beeb's security team

The world's oldest national broadcaster, the venerable British Broadcasting Corporation, has told staff they shouldn't keep the TikTok app on a BBC corporate device unless there is a "justified business reason."…

☐ β˜† βœ‡ The Register - Security

Vessels claiming to be Chinese warships are messing with passenger planes

March 20th 2023 at 07:29

Australian airline Qantas warns pilots to keep calm and carry on amid reports of satnav and altimeter jamming

Australian airline Qantas issued standing orders to its pilots last week advising them that some of its fleet experienced interference on VHF stations from sources purporting to be the Chinese Military.…

☐ β˜† βœ‡ The Register - Security

Police pounce on 'pompompurin' – alleged mastermind of BreachForums

March 20th 2023 at 06:02

Crypto laundering service gets cleaned up by police and SVB mess draws in more criminals

In Brief A man accused of being the head of one of the biggest criminal online souks, BreachForums, has been arrested in Peekskill, New York.…

☐ β˜† βœ‡ The Register - Security

TikTok cannot be considered a private company, says Australian report

March 19th 2023 at 23:30

ALSO: Japan ends chip supply crimp on South Korea, APAC infosec spending surges; Philippines SIM registration stalls

Asia In Brief ByteDance, the Chinese developer of TikTok, "can no longer be accurately described as a private enterprise" and is instead intertwined with China's government, according to a report [PDF] submitted to Australia's Select Committee on Foreign Interference through Social Media.…

☐ β˜† βœ‡ The Register - Security

BianLian ransomware crew goes 100% extortion after free decryptor lands

March 19th 2023 at 13:37

No good deed goes unpunished, or something like that

The BianLian gang is ditching the encrypting-files-and-demanding-ransom route and instead is going for full-on extortion.…

☐ β˜† βœ‡ The Register - Security

You've been pwned, how much will each stolen customer SSN cost you? How about $7.5k?

March 18th 2023 at 14:02

At the very least, with other costs on top

A Florida healthcare group has settled a class-action lawsuit after thieves stole more than 447,000 patients' names, Social Security numbers, and sensitive medical information, from its servers.…

☐ β˜† βœ‡ The Register - Security

Google: Turn off Wi-Fi calling, VoLTE to protect your Android from Samsung hijack bugs

March 17th 2023 at 20:35

Four flaws open mobiles, cars to remote-control at baseband level with just a phone number

Google security analysts have warned Android device users that several zero-day vulnerabilities in some Samsung chipsets could allow an attacker to completely hijack and remote-control their handsets knowing just the phone number.…

☐ β˜† βœ‡ The Register - Security

Eufy security cams 'ignore cloud opt-out, store unique IDs' of anyone who walks by

March 17th 2023 at 19:30

Gadget maker accused of 'corporate voyeurism' by gathering up footage against your wishes

A lawsuit filed against eufy security cam maker Anker Tech claims the biz assigns "unique identifiers" to the faces of any person who walks in front of its devices – and then stores that data in the cloud, "essentially logging the locations of unsuspecting individuals" when they stroll past.…

☐ β˜† βœ‡ The Register - Security

Feds arrest and charge exiled Chinese billionaire over massive crypto fraud

March 17th 2023 at 02:59

This one has it all: Donald Trump’s inner circle, a Beijing bot backlash, conspiracy theories, and more

Meet the newest member of the crypto rogues' gallery: Ho Wan Kwok, aka Guo Wengui, aka Miles Guo, whom the US Department of Justice on Wednesday arrested over what investigators have described as a "sprawling and complex scheme … to solicit investments in various entities and programs through false statements and representations to hundreds of thousands of Kwok's online followers."…

☐ β˜† βœ‡ The Register - Security

Here's how Chinese cyber spies exploited a critical Fortinet bug

March 17th 2023 at 01:00

Looks to be the same baddies attacking VMware hypervisors last year

Suspected Chinese spies have exploited a critical Fortinet bug, and used custom networking malware to steal credentials and maintain network access, according to Mandiant security researchers.…

☐ β˜† βœ‡ The Register - Security

FTX inner circle helped itself to $3.2B, liquidators say

March 16th 2023 at 22:04

SBF alone pocketed $2.2B, or so this bankruptcy paperwork goes

In fresh filings in the FTX bankruptcy case, the cryptocurrency-exchange-slash-hedge-fund's liquidators sayΒ they've uncovered $3.2 billion (Β£2.6b) in payments and loans made to disgraced FTX founder Sam Bankman-Fried and his inner circle. …

☐ β˜† βœ‡ The Register - Security

Got Conti? Here's the ransomware cure to avoid paying up

March 16th 2023 at 20:28

Kaspersky cracks the code, so get busy before the next update comes

Good news for ransomware victims: Kaspersky security researchers say they've cracked the Conti ransomware code and released a decryptor tool after uncovering leaked data belonging to the notorious Russian crime group.…

☐ β˜† βœ‡ The Register - Security

UK.gov bans TikTok from its devices as a 'precaution' over spying fears

March 16th 2023 at 14:34

Gov staff using it on personal mobes just fine... it's not like ministers use WhatsApp etc for business ... oh wait

The United Kingdom government has banned use of Chinese social media platform TikTok among ministers and officials on their work devices as a β€œprecautionary” measure over worries the app is used to snoop on Brits.…

☐ β˜† βœ‡ The Register - Security

Hands up who DIDN'T exploit this years-old flaw to ransack a US govt web server...

March 15th 2023 at 23:00

Why patching matters: Everyone seemingly had a crack at security bug

Multiple criminals, including at least potentially one nation-state group, broke into a US federal government agency's Microsoft Internet Information Services web server by exploiting a critical three-year-old Telerik bug to achieve remote code execution.…

☐ β˜† βœ‡ The Register - Security

Cancer patient sues hospital after ransomware gang leaks her nude medical photos

March 15th 2023 at 20:05

Victim offered two years of credit monitoring after highly sensitive records dumped online

A cancer patient whose nude medical photos and records were posted online after they were stolen by a ransomware gang, has sued her healthcare provider for allowing the "preventable" and "seriously damaging" leak.…

☐ β˜† βœ‡ The Register - Security

SVB collapse's mix of money, urgency and uncertainty makes it irresistible to scammers

March 15th 2023 at 05:46

Phishing, dodgy domain names, and sophisticated attacks already deployed

The collapse of Silicon Valley Bank (SVB) late last week sent tremors through the global financial system, creating opportunities for short-sellers – and numerous species of scammer.…

☐ β˜† βœ‡ The Register - Security

China sought control of submarine cables to spy, says Micronesia

March 15th 2023 at 03:29

Outgoing president alleges Beijing is systematically bullying strategically located island paradise

The outgoing president of the Federated States of Micronesia (FSM), David Panuelo, penned a lengthy letter last week accusing Beijing of rampant bribery, spying and other tactics – including an attempt to take control of the nation's submarine cables and telecoms infrastructure.…

☐ β˜† βœ‡ The Register - Security

Microsoft: Patch this severe Outlook bug that Russian miscreants exploited

March 14th 2023 at 23:59

Plus: Fixes for SAP, Adobe. Android, Chrome

Patch Tuesday Microsoft's March Patch Tuesday includes new fixes for 74 bugs, two of which are already being actively exploited, and nine that are rated critical. Let's start with the two that miscreants found before Redmond issued a fix.…

☐ β˜† βœ‡ The Register - Security

Microsoft squashes Windows bug exploited to inflict ransomware misery

March 14th 2023 at 19:01

Not-so-smart SmartScreen flagged up by Googlers

Criminals are exploiting a Microsoft SmartScreen bug to deliver Magniber ransomware, potentially infecting hundreds of thousands of devices, without raising any security red flags, according to Google's Threat Analysis Group (TAG).…

☐ β˜† βœ‡ The Register - Security

India floats idea of dedicated tribunal to handle online offences

March 13th 2023 at 07:58

Consultation for the long-awaited Digital India Act is finally under way although the draft law's still not been revealed

India's government has started to consult some proposed details of its long-awaited Digital India Act, including a declaration that the bill needed a dedicated adjudicatory tool for offenses committed online.…

☐ β˜† βœ‡ The Register - Security

UK refreshes national security plan to stop more of China's secret-stealing cyber-tricks

March 14th 2023 at 07:40

A threat that needs two orgs to tackle it: the 'Integrated Security Fund' and the 'National Protective Security Authority'

Britain's domestic intelligence service MI5 will oversee a new agency tasked with helping organizations combat Chinese cyber-spies and other threats.…

☐ β˜† βœ‡ The Register - Security

LockBit brags: We'll leak thousands of SpaceX blueprints stolen from supplier

March 13th 2023 at 23:40

And also, Ring hit with ransomware, too? No, says Amazon

Ransomware gang Lockbit has boasted it broke into Maximum Industries, which makes parts for SpaceX, and stole 3,000 proprietary schematics developed by Elon Musk's rocketeers.…

☐ β˜† βœ‡ The Register - Security

Zoll Medical says intruders had 1M+ patient, staff records at their fingertips

March 13th 2023 at 21:30

Names, addresses, SSNs all up for grabs

Medical device and software maker Zoll Medical says the personal and health information of more than a million people, including patients and employees, may have been stolen by crooks in January.…

☐ β˜† βœ‡ The Register - Security

CISA joins forces with Women in CyberSecurity to break up the boy's club

March 13th 2023 at 12:32

Also, the FBI just admitted to bypassing warrants by buying cellphone location data, and this week's actionable items

in brief Cybersecurity and Infrastructure Security Agency's director Jen Easterly has been outspoken in her drive to bring more women into the security industry, and this year for International Women's Day her agency formalized that pledge by announcing a partnership with nonprofit Women in CyberSecurity (WiCyS).…

☐ β˜† βœ‡ The Register - Security

The UK's bad encryption law can't withstand global contempt

March 13th 2023 at 10:32

Any sufficiently stupid technology is indistinguishable from magical thinking

Opinion Around the world, a vital technology is failing. Just as massive solar flares fry satellites and climate-change superstorms overwhelm flood defences, so a new surge of ridiculous IT-related events is burning out irony meters across the globe.…

☐ β˜† βœ‡ The Register - Security

Cutting complexity

March 13th 2023 at 08:52

Ensuring cybersecurity defences do more with less

Webinar It's like living in a fever dream out there in the world of cybersecurity. More and more sophisticated attacks, a tsunami of solutions offering a gilt-edged escape from the need to constantly reconfigure your defences, and relentless pressure to always stay one step ahead of the hackers.…

☐ β˜† βœ‡ The Register - Security

Google euthanizes Chrome Cleanup Tool because it no longer has a purpose

March 11th 2023 at 00:28

Times have changed and unwanted software on Windows is a rarity (unless you count Windows itself)

Google is bidding adieu to an application that enabled Chrome users on Windows systems to get rid of unwanted software.…

☐ β˜† βœ‡ The Register - Security

What happens if you 'cover up' a ransomware infection? For Blackbaud, a $3m charge

March 10th 2023 at 22:05

File under cost of doing business

Blackbaud has agreed to pay $3 million to settle charges that it made misleading disclosures about a 2020 ransomware infection in which crooks stole more than a million files on around 13,000 of the cloud software slinger's customers.…

☐ β˜† βœ‡ The Register - Security

Electronics market shows US-China decoupling will hike inflation and slow growth

March 10th 2023 at 18:00

Singapore's central bank has a gloomy vision of the future

According to the Monetary Authority of Singapore (MAS), trade barriers between US and China have resulted in geoeconomic fragmentation and will likely result in slower global growth and higher inflation.…

☐ β˜† βœ‡ The Register - Security

Acronis downplays intrusion after 12GB trove leaks online

March 10th 2023 at 03:45

Cyber-thief said goal was to 'humiliate' data-protection biz

The CISO of Acronis has downplayed what appeared to be an intrusion into its systems, insisting only one customer was affected, using stolen credentials, and that all other data remains safe.…

☐ β˜† βœ‡ The Register - Security

Catholic clergy surveillance org 'outs gay priests'

March 10th 2023 at 02:30

Religious non-profit allegedly hoovered up location data from dating apps to ID clerics

A Catholic clergy conformance organization has reportedly been buying up tracking data from mobile apps to identify gay priests, and providing that information to bishops around America.…

☐ β˜† βœ‡ The Register - Security

FBI and international cops catch a NetWire RAT

March 10th 2023 at 01:33

Malware-seekers were diverted to the Feds, severing a Croatian connection

International law enforcement agencies have claimed another victory over cyber criminals, after seizing the website, and taking down the infrastructure operated by crims linked to the NetWire remote access trojan (RAT).…

☐ β˜† βœ‡ The Register - Security

AT&T blames marketing bods for exposing 9M accounts

March 9th 2023 at 22:30

Says it was old and boring data, so that's OK, then ...

AT&T has confirmed that miscreants had access to nine million of its wireless customers' account details after a vendor's network was broken into in January.…

☐ β˜† βœ‡ The Register - Security

US House reps, staff health data swiped in cyber-heist

March 9th 2023 at 21:27

Data for sale via dark web, Senate in line of fire, too

Health data and other personal information of members of Congress and staff were stolen during a breach of servers run by DC Health Care Link and are now up for sale on the dark web.…

☐ β˜† βœ‡ The Register - Security

Refreshed from its holiday, Emotet has gone phishing

March 9th 2023 at 18:27

Notorious botnet starts spamming again after a three-month pause

Emotet is back. After another months-long lull since a spate of attacks in November 2022, the notorious malware operation that has already survived a law enforcement takedown and various periods of inactivity began sending out malicious emails on Tuesday morning.…

☐ β˜† βœ‡ The Register - Security

Suspected Chinese cyber spies target unpatched SonicWall devices

March 9th 2023 at 02:26

They've been lurking in networks since at least 2021

Suspected Chinese cyber criminals have zeroed in on unpatched SonicWall gateways and are infecting the devices with credential-stealing malware that persists through firmware upgrades, according to Mandiant.…

☐ β˜† βœ‡ The Register - Security

Dems, Repubs eye up ban on chat apps they don't like

March 9th 2023 at 01:28

Clock is ticking for TikTok and other foreign natter-ware

On Tuesday a bipartisan group of a dozen US senators introduced a bill to authorize the Commerce Department to ban information and communications technology products and services deemed threats to national security.…

☐ β˜† βœ‡ The Register - Security

Securing ways to share workplace passwords

March 8th 2023 at 09:30

Keeper protects your team’s credentials without slowing down business

Sponsored Feature When the first computer system passwords were set in 1961, few people needed to carry personal credentials to get through daily life. Nowadays, login credentials are ubiquitous across nearly every application, software and web service.…

❌