FreshRSS

πŸ”’
☐ β˜† βœ‡ The Register - Security

Uber driver info stolen yet again: This time from law firm

April 3rd 2023 at 20:27

Never mind software supply chain attacks, lawyers are the new soft target?

Uber has had more of its internal data stolen from a third party that suffered a security breach. This time, the personal info of the app's drivers was swiped by miscreants from the IT systems of law firm Genova Burns.…

☐ β˜† βœ‡ The Register - Security

April brings tulips, taxes ... and phisherfolk scammers

April 3rd 2023 at 18:39

Tactical#Octopus: Don't let users click on that zip file

The last few days of America's tax season are stressful enough, dealing with deadlines and, increasingly, online scams. Now comes another one, a sophisticated and ongoing phishing campaign by a threat group dubbed "Tactical#Octopus" that is using tax-related lures to spread malware.…

☐ β˜† βœ‡ The Register - Security

Capita: Cyber-attack broke some of our IT systems

April 3rd 2023 at 15:33

Staff regain access to Microsoft apps, tech outsourcer still working to restore services for some

Capita – everyone's favorite outsourcing badass – is still working to restore services for some customers after admitting the IT outage of certain services on Friday was caused by a cyber attack and efforts to contain the infiltration.…

☐ β˜† βœ‡ The Register - Security

Keeping secrets safe

April 3rd 2023 at 13:22

How to implement robust secret and identity management

Webinar Keeping digital authentication credentials safe is a highly sensitive task in an ever-evolving IT landscape, made more difficult when you consider the ongoing shift from static to dynamic applications aligned with increasingly distributed teams of workers.…

☐ β˜† βœ‡ The Register - Security

Western Digital confirms digital burglary, calls the cops

April 3rd 2023 at 11:58

Thinks info from internal systems 'obtained' by miscreant, unsure of nature or scope data

Western Digital is today dealing with a "network security incident" after detecting a break-in into its internal systems by an unauthorized third party.…

☐ β˜† βœ‡ The Register - Security

3CX thought supply chain attack was a false positive

April 3rd 2023 at 07:32

'It's not unusual for VoIP apps' says CEO

Updated The CEO of VoIP software provider 3CX said his team tested its products in response to alerts of suspicious activity that was later found to be a supply chain attack, and assessed reports of issues with the software as a false positive.…

☐ β˜† βœ‡ The Register - Security

Vietnam threatens to cut off two million mobile subscribers

April 3rd 2023 at 04:33

To scupper scams, account-holders must hand over personal info or else

Almost two million mobile phone subscribers in Vietnam are at risk of having their services severed, thanks to a new government policy that seeks to curb spam.…

☐ β˜† βœ‡ The Register - Security

School principal resigns after writing $100,000 check to Elon Musk impersonator

April 3rd 2023 at 01:58

ALSO: DJI forgets the 'B' in 'BCC,' and this week's critical known exploits

In Brief The principal of a Florida science and technology charter school has resigned after allegedly writing a $100,000 check to an Elon Musk impersonator using school funds.…

☐ β˜† βœ‡ The Register - Security

Ukrainian cops nab suspects accused of stealing $4.3m from victims across Europe

April 1st 2023 at 07:25

If the price looks too good to be true, it probably is

Ukrainian cops have arrested two suspects and detained 10 others for their alleged roles in a cybercrime gang that used phishing scams and phony online marketplaces to steal more than $4.3 million from over 1,000 victims across Europe.…

☐ β˜† βœ‡ The Register - Security

NYPD blues: Cops ignored 93 percent of surveillance law rules

March 31st 2023 at 20:06

Who watches the watchmen? The Office of the Inspector General

Back in July 2020, then New York City Mayor Bill de Blasio signed the Public Oversight of Surveillance Technology (POST) Act into law, which required the New York Police Department to reveal how it uses surveillance technology and to formulate surveillance policies.…

☐ β˜† βœ‡ The Register - Security

Psst! Infosec bigwigs: Wanna be head of security at HM Treasury for Β£50k?

March 31st 2023 at 11:40

Juicy private sector job vs … money off a season travel ticket

Given the importance of the Treasury department's function to Britain, Reg readers might expect the Head of Cyber Security vacancy currently being advertised would come with a salary that reflects its criticality.…

☐ β˜† βœ‡ The Register - Security

NHS Highland 'reprimanded' by data watchdog for BCC blunder with HIV patients

March 31st 2023 at 09:35

'Serious breach of trust' says ICO, 'stakes too high' for mistakes in cases like this

In a classic email snafu NHS Highland sent messages to 37 patients infected with HIV and inadvertently used carbon copy (CC) instead of Blind Carbon Copy meaning the recipients could see each other’s email addresses.…

☐ β˜† βœ‡ The Register - Security

Pro-Russia cyber gang Winter Vivern puts US, Euro lawmakers in line of fire

March 31st 2023 at 07:30

Winter is coming for NATO countries

A cyber spy gang supporting Russia is targeting US elected officials and their staffers, in addition to European lawmakers, using unpatched Zimbra Collaboration software in two campaigns spotted by Proofpoint.…

☐ β˜† βœ‡ The Register - Security

Leaked IT contractor files detail Kremlin's stockpile of cyber-weapons

March 31st 2023 at 01:24

Snowden-esque 'Vulkan' dossier links Moscow firm to FSB, GRU, SRV

An unidentified whistleblower has provided several media organizations with access to leaked documents from NTC Vulkan – a Moscow IT consultancy – that allegedly show how the firm supports Russia's military and intelligence agencies with cyber warfare tools.…

☐ β˜† βœ‡ The Register - Security

Azure blunder left Bing results editable, MS 365 accounts potentially exposed

March 30th 2023 at 23:30

'BingBang' boo-boo affected other internal Microsoft apps, too

An Azure Active Directory (AAD) misconfiguration by Microsoft in one of its own cloud-hosted applications could have allowed miscreants to subvert the IT giant's Bing search engine – even changing search results.…

☐ β˜† βœ‡ The Register - Security

AlienFox malware caught in the cloud hen house

March 30th 2023 at 21:30

Malicious toolkit targets misconfigured hosts in AWS and Office 365

A fast-evolving toolkit that can be used to compromise email and web hosting services represents a disturbing evolution of attacks in the cloud, which for the most part have previously been confined to mining cryptocurrencies.…

☐ β˜† βœ‡ The Register - Security

Do you use comms software from 3CX? What to do next after biz hit in supply chain attack

March 30th 2023 at 16:25

Miscreants hit downstream customers with infostealers

Two security firms have found what they believe to be a supply chain attack on communications software maker 3CX – and the vendor's boss is advising users to switch to the progressive web app until the 3CX desktop client is updated.…

☐ β˜† βœ‡ The Register - Security

Microsoft uses carrot and stick with Exchange Online admins

March 30th 2023 at 14:27

If you need extra time to dump RPS, OK, but email from unsupported Exchange servers is blocked till they’re up to date

Some Exchange Online users who have the RPS feature turned off by Microsoft can now have it re-enabled – at least until September when the tool is retired.…

☐ β˜† βœ‡ The Register - Security

The most important email conversation you will ever have

March 30th 2023 at 09:14

Securing your business against BEC

Webinar Business email compromise (BEC) is possibly the worst of cybercrimes because it abuses trust. It feeds on relationships carefully nurtured over decades and erodes a confidence which is foundational to cooperation, and progress.…

☐ β˜† βœ‡ The Register - Security

Warning: Your wireless networks may leak data thanks to Wi-Fi spec ambiguity

March 30th 2023 at 06:29

How someone can nab buffered info, by hook or by kr00k

Ambiguity in the Wi-Fi specification has left the wireless networking stacks in various operating systems vulnerable to several attacks that have the potential to expose network traffic.…

☐ β˜† βœ‡ The Register - Security

Another year, another North Korean malware-spreading, crypto-stealing gang named

March 30th 2023 at 04:40

Mandiant identifies 'moderately sophisticated' but 'prolific' APT43 as global menace

Google Cloud's recently acquired security outfit Mandiant has named a new nasty from North Korea: a cyber crime gang it calls APT43 and accuses of a five-year rampage.…

☐ β˜† βœ‡ The Register - Security

Smugglers busted sneaking tech into China

March 30th 2023 at 03:02

'Intel inside' a suspiciously baggy t-shirt gave the game away – as did a truckload of parts

International Talk Like a Pirate Day is still months away – circle September 19 on your calendar, me hearties! – but The Register has found news of technology smuggling in China that suggests a buccaneering approach to imports.…

☐ β˜† βœ‡ The Register - Security

Malware disguised as Tor browser steals $400k in cryptocash

March 30th 2023 at 01:30

Beware of third party downloads

Clipboard-injector malware disguised as Tor browser installers has been used to steal about $400,000 in cryptocurrency from nearly 16,000 users worldwide so far in 2023, according to Kaspersky researchers.…

☐ β˜† βœ‡ The Register - Security

Microsoft Defender shoots down legit URLs as malicious

March 29th 2023 at 18:31

Those hoping to use nefarious websites like, er, Zoom are overrun by alerts. Redmond 'investigating'

Updated Microsoft's at-times-glitchy Defender service is again causing headaches for IT admins by flagging legitimate URLs as malicious.…

☐ β˜† βœ‡ The Register - Security

EU mandated messaging platform love-in is easier said than done: Cambridge boffins

March 29th 2023 at 14:28

Digital Market Act interoperability requirement a social challenge as well as a technical one

By March 2024, instant messaging and real-time media apps operated by large tech platforms in Europe will be required to communicate with other services, per the EU's Digital Markets Act (DMA).…

☐ β˜† βœ‡ The Register - Security

FTX cryptovillain Sam Bankman-Fried charged with bribing Chinese officials

March 29th 2023 at 10:24

Court gives him new rules: Use one laptop, while living with the 'rents.

US authorities have charged FTX co-founder Sam Bankman-Fried (aka SBF) with attempting to bribe Chinese officials with $40 million worth of cryptocurrency in exchange for unfreezing trading accounts.…

☐ β˜† βœ‡ The Register - Security

DDoS DNS attacks are old-school, unsophisticated … and they’re back

March 29th 2023 at 08:34

So why would you handle them on your own?

Sponsored Feature Ransomware may currently be the biggest bogeyman for cybersecurity pros, law enforcement, and governments, but it shouldn't divert us from more traditional, but still very disruptive threats.…

☐ β˜† βœ‡ The Register - Security

China urges Apple to improve security and privacy

March 29th 2023 at 01:27

It's a juicy market that welcomes foreign investment, National development boss reminds Tim Cook

Senior Chinese government officials have urged Apple CEO Tim Cook to improve the security and privacy features of his company's products.…

☐ β˜† βœ‡ The Register - Security

Apple patches all the iThings, including iOS 15 hole under attack right now

March 28th 2023 at 22:16

Issue identified in February but owners of older kit weren't warned

Happy belated Patch Tuesday from Cupertino: Apple has issued security updates for almost every piece of code it slings - including a fix for a vulnerability in older iOS devices the iGiant believes is under attack right now.…

☐ β˜† βœ‡ The Register - Security

Google again accused of willfully destroying evidence in Android antitrust battle

March 28th 2023 at 20:09

Starting to see a pattern here? Judge seems to think so

Updated Google Chat histories handed over by the web giant in ongoing Android antitrust litigation reveal the biz has been systematically destroying evidence, according to those suing the big G.…

☐ β˜† βœ‡ The Register - Security

President Biden kind of mostly bans commercial spyware from US govt

March 28th 2023 at 02:45

Executive order has loopholes for Uncle Sam's snoop tools and American-made code

US president Joe Biden on Monday issued an executive order on the "prohibition on use by the United States government of commercial spyware that poses risks to national security" – a title that is not quite as simple it seems.…

☐ β˜† βœ‡ The Register - Security

Lawyers cough up $200k after health data stolen in Microsoft Exchange pillaging

March 27th 2023 at 22:45

In addition to $100k given to LockBit

New York law firm Heidell, Pittoni, Murphy and Bach (HPMB) has agreed to pay $200,000 to settle a data-breach lawsuit related to the now-notorious Hafnium Microsoft Exchange attacks that siphoned sensitive data from victims around the world. …

☐ β˜† βœ‡ The Register - Security

Gone in 120 seconds: Tesla Model 3 child's play for hackers

March 27th 2023 at 11:32

Plus OIG finds Uncle Sam fibbed over Login.gov

In brief A team of hackers from French security shop Synacktiv have won $100,000 and a Tesla Model 3 after subverting the Muskmobile's entertainment system, and from there opening up the car's core management systems.…

☐ β˜† βœ‡ The Register - Security

China crisis is a TikToking time bomb

March 27th 2023 at 09:30

ByteDance with the devil if you dare

Opinion As country after country bans TikTok from official systems, it’s fair to ask what’s so dodgy about a social network filled with dance crazes, makeup advice and cats.…

☐ β˜† βœ‡ The Register - Security

CISA unleashes Untitled Goose Tool to honk at danger in Microsoft's cloud

March 24th 2023 at 19:16

Not a headline we expected to write today

American cybersecurity officials have released an early-warning system to protect Microsoft cloud users.…

☐ β˜† βœ‡ The Register - Security

GitHub publishes RSA SSH host keys by mistake, issues update

March 24th 2023 at 13:34

Getting connection failures? Don't panic. Get new keys

GitHub has updated its SSH keys after accidentally publishing the private part to the world. Whoops.…

☐ β˜† βœ‡ The Register - Security

French parliament says oui to AI surveillance for 2024 Paris Olympics

March 24th 2023 at 06:24

LibertΓ©, Γ©galitΓ©, reconnaissance faciale for all

Despite the opposition of 38 civil society groups, the French National Assembly has approved the use of algorithmic video surveillance during the 2024 Paris Olympics.…

☐ β˜† βœ‡ The Register - Security

Uncle Sam reveals it sent cyber-soldiers to Albania to hunt for Iranian threats

March 24th 2023 at 01:05

'Hunt forward' teams of this sort aid with defense and learn how attackers like Tehran operate

US Cyber Command operators have confirmed they carried out an online defensive mission in Albania, in response to last year's cyber attacks against the local government.…

☐ β˜† βœ‡ The Register - Security

Critical infrastructure gear is full of flaws, but hey, at least it's certified

March 23rd 2023 at 21:59

Security researchers find bugs, big and small, in every industrial box probed

Devices used in critical infrastructure are riddled with vulnerabilities that can cause denial of service, allow configuration manipulation, and achieve remote code execution, according to security researchers.…

☐ β˜† βœ‡ The Register - Security

Secure mail

March 23rd 2023 at 09:48

Protection from business email compromise

Webinar In the distant past, a master forger with a quill could fake a signature on the end of a letter but at least then you had time to consider the potential for fraud before any damage could be done. In the digital age of email, it's increasingly hard to spot a scam's threat to your security and react in time.…

☐ β˜† βœ‡ The Register - Security

Attackers hit Bitcoin ATMs to steal $1.5 million in crypto cash

March 23rd 2023 at 09:02

Terminal maker General Bytes shutters its cloud business after second breach in seven months

Unidentified miscreants have siphoned cryptocurrency valued at more than $1.5 million from Bitcoin ATMs by exploiting an unknown flaw in digicash delivery systems.…

☐ β˜† βœ‡ The Register - Security

Bogus ChatGPT extension steals Facebook cookies

March 23rd 2023 at 07:29

All aboard the chatbot hype train! Next stop: Fraud

Google has removed a ChatGPT extension from the Chrome store that steals Facebook session cookies – but not before more than 9,000 users installed the account-compromising bot.…

☐ β˜† βœ‡ The Register - Security

B-List celebs including Lindsay Lohan fined after crypto shill probe

March 23rd 2023 at 06:30

Didn't disclose payments as mastermind pumped up value of tokens with fake trades

Eight very B-list celebrities have agreed to cough up fines after being accused of shilling a cryptocurrency without disclosing they were paid to do so, while the chap who apparently paid them has been charged with fraud.…

☐ β˜† βœ‡ The Register - Security

South Korea fines McDonald's for data leak from raw SMB share

March 23rd 2023 at 02:29

British American Tobacco, Samsung, also burgered up their infosec

South Korea's Personal Information Protection Commission has fined McDonald's, British American Tobacco, and Samsung for privacy breaches.…

☐ β˜† βœ‡ The Register - Security

Cisco kindly reveals proof of concept attacks for flaws in rival Netgear's kit

March 22nd 2023 at 22:57

Maybe this is deserved given the problem's in a hidden telnet service

Public proof-of-concept exploits have landed for bugs in Netgear Orbi routers – including one critical command execution vulnerability. …

☐ β˜† βœ‡ The Register - Security

Journalist hurt by exploding USB bomb drive

March 22nd 2023 at 22:09

Now that's a flash bang

Police in Ecuador are investigating attacks on media organizations across the country after a journalist was injured by an exploding USB flash drive.…

☐ β˜† βœ‡ The Register - Security

German political parties accused of microtargeting voters on Facebook

March 22nd 2023 at 12:31

Country's super strong data rights under magnifying glass after half a dozen complaints filed

Remember the Who Targets Me browser extension from privacy activists at Noyb? The group yesterday filed explosive complaints based on log records from the extension that claim six of Germany's political parties broke European data law when they targeted voters on Facebook's adtech platform.…

☐ β˜† βœ‡ The Register - Security

Unknown actors deploy malware to steal data in occupied regions of Ukraine

March 22nd 2023 at 07:32

If this is Kyiv's work, Russia can Crimea river

A cyber espionage campaign targeting organizations in Russian-occupied regions of Ukraine is using novel malware to steal data, according to Russia-based infosec software vendor Kaspersky.…

☐ β˜† βœ‡ The Register - Security

India's absurd infosec reporting rules get just 15 followers

March 22nd 2023 at 03:30

CERT-In was told its six-hour notification requirement was a bad idea – now it knows just how bad

India's rules requiring local organizations to report infosec incidents within six hours of detection have been observed by a mere 15 entities/…

☐ β˜† βœ‡ The Register - Security

Xi, Putin declare intent to rule the world of AI, infosec

March 22nd 2023 at 01:58

'Technological sovereignty is the key to sustainability' states Russian despot

Russian president Vladimir Putin and his Chinese counterpart Xi Jinping have set themselves the goal of dominating the world of information technology.…

☐ β˜† βœ‡ The Register - Security

BreachForums shuts down ... but the RaidForums cybercrime universe will likely spawn a trilogy

March 22nd 2023 at 00:45

Admins decide reviving crime-mart is dangerous, hint at new chapter

BreachForums has reportedly shut down for good, just days after US authorities arrested the online criminal marketplace's alleged chief administrator.…

☐ β˜† βœ‡ The Register - Security

You just gonna take that AWS? Let Microsoft school your users on cloud security?

March 21st 2023 at 20:43

And Google Cloud is next

Microsoft has torn the wraps off its multi-cloud security benchmark (MCSB), which replaces the four-year-old Azure Security Benchmark. Crucially, as the name suggests, it now has usage and configuration guidance that reaches into rival environments.…

☐ β˜† βœ‡ The Register - Security

Ex-Meta security staffer accuses Greece of spying on her phone

March 21st 2023 at 08:31

Beware of Greeks bearing GIFs

Meta's former security policy manager, who split her time between the US and Greece, is reportedly suing the Hellenic national intelligence service for hacking her phone.…

☐ β˜† βœ‡ The Register - Security

Putin to staffers: Throw out your iPhones, or 'give it to the kids'

March 21st 2023 at 06:30

April Fools should use Russian or Chinese tech instead, Kremlin advises

Advisors and staff to Russia's maximum leader have been told to ditch their iPhones by the end of the month. Or, for those who don't want to throw their Apple devices in the bin, the other option is to "give it to the kids," according to a local Kommersant report.…

☐ β˜† βœ‡ The Register - Security

Google suspends top Chinese shopping app Pinduoduo

March 21st 2023 at 05:58

Alleges it’s infected with malware – but not the version in its own digital tat bazaar

Google has suspended Chinese shopping app Pinduoduo from its Play store because versions of the software found elsewhere have included malware.…

☐ β˜† βœ‡ The Register - Security

Australian FinTech takes itself offline to deal with cyber incident that caused data leak

March 21st 2023 at 03:58

Latitude blames a 'major vendor' for its woes. Is that a vendor? A cloud? Whoever they are, they're in trouble

Latitude Financial has blamed a supplier for leaking creds that caused vast PII leak Australian outfit Latitude Financial has taken itself offline, and even stopped serving customers, while it tries to clean up an attack on its systems.…

☐ β˜† βœ‡ The Register - Security

Ferrari in a spin as crims steal a car-load of customer data

March 21st 2023 at 01:45

Speeds away from the very suggestion it would ever pay a ransom

Italian automaker Ferrari has warned its well-heeled customers that their personal data may be at risk.…

☐ β˜† βœ‡ The Register - Security

Privacy fail: Pictures cropped, redacted by Google Pixel phones can be recovered

March 20th 2023 at 21:13

aCropalypse Now, starring any 2018-or-later device

Updated If you've owned a Google Pixel smartphone since the 3 series came out in 2018, bad news: any screenshot that you've cropped or redacted on your Pixel can be potentially restored without much fuss.…

☐ β˜† βœ‡ The Register - Security

BBC to staff: Uninstall TikTok from our corporate kit unless you can 'justify' having it

March 20th 2023 at 12:34

Those with 'sensitive' work-related information told to contact Beeb's security team

The world's oldest national broadcaster, the venerable British Broadcasting Corporation, has told staff they shouldn't keep the TikTok app on a BBC corporate device unless there is a "justified business reason."…

☐ β˜† βœ‡ The Register - Security

Vessels claiming to be Chinese warships are messing with passenger planes

March 20th 2023 at 07:29

Australian airline Qantas warns pilots to keep calm and carry on amid reports of satnav and altimeter jamming

Australian airline Qantas issued standing orders to its pilots last week advising them that some of its fleet experienced interference on VHF stations from sources purporting to be the Chinese Military.…

❌