FreshRSS

πŸ”’
☐ β˜† βœ‡ The Register - Security

Another zero-click Apple spyware maker just popped up on the radar again

April 12th 2023 at 00:42

Pegasus, pssh, you so 2000-and-late

Malware reportedly developed by a little-known Israeli commercial spyware maker has been found on devices of journalists, politicians, and an NGO worker in multiple countries, say researchers. …

☐ β˜† βœ‡ The Register - Security

April Patch Tuesday: Ransomware gangs already exploiting this Windows bug

April 11th 2023 at 23:04

Plus Google, SAP, Adobe and Cisco emit fixes

Microsoft patched 97 security flaws today for April's Patch Tuesday including one that has already been found and exploited by miscreants attempting to deploy Nokoyawa ransomware.…

☐ β˜† βœ‡ The Register - Security

Azure admins warned to disable shared key access as backdoor attack detailed

April 11th 2023 at 13:00

The default is that sharing is caring as Redmond admits: 'These permissions could be abused'

A design flaw in Microsoft Azure – that shared key authorization is enabled by default when creating storage accounts – could give attackers full access to your environment, according to Orca Security researchers.…

☐ β˜† βœ‡ The Register - Security

40% of IT security pros say they've been told not to report a data leak

April 11th 2023 at 09:37

Plus: KFC, Pizza Hut owner spills more beans on ransomware hit... latest critical flaws... and more

In Brief More than 40 percent of surveyed IT security professionals say they've been told to keep network breaches under wraps despite laws and common decency requiring disclosure.…

☐ β˜† βœ‡ The Register - Security

How much to infect Android phones via Google Play store? How about $20k

April 10th 2023 at 23:01

Or whatever you managed to haggle with these miscreants

If you want to sneak malware onto people's Android devices via the official Google Play store, it may cost you about $20,000 to do so, Kaspersky suggests.…

☐ β˜† βœ‡ The Register - Security

Inside FTX: Jokes about misplaced funds, diabolical IT, poor oversight, and worse

April 10th 2023 at 21:43

How's the saying go? $50m here, $50m there, pretty soon you're talking real money

The liquidators picking over the remains of FTX have released their first formal report into Sam Bankman-Fried's imploded empire – and it somehow appears things are worse than feared.…

☐ β˜† βœ‡ The Register - Security

Apple squashes iOS, macOS zero-day bugs already exploited by snoops

April 10th 2023 at 21:01

Keep calm and install patches before abuse becomes widespread

Apple rolled out patches on Good Friday to its iOS, iPadOS, and macOS operating systems and the Safari web browser to address vulnerabilities found by Google and Amnesty International that were exploited in the wild.…

☐ β˜† βœ‡ The Register - Security

Google to kill Dropcam, Nest Secure hardware next year

April 10th 2023 at 18:58

Great, more company for Stadia, Duo and pals in the graveyard

Owners of Dropcam security cameras and Nest Secure systems have been given an unwelcome deadline from Google: their smart home products will be shut off April 8 next year.…

☐ β˜† βœ‡ The Register - Security

Microsoft, Fortra are this fed up with cyber-gangs abusing Cobalt Strike

April 10th 2023 at 16:29

Oh, sure, let's play a game of legal and technical whack-a-mole

Microsoft and Fortra are taking legal and technical actions to thwart cyber-criminals from using the latter company's Cobalt Strike software to distribute malware.…

☐ β˜† βœ‡ The Register - Security

When it comes to technology, securing your future means securing your present

April 10th 2023 at 13:58

How to build cyber resiliency in the face of complexity

Sponsored Feature Most economies and business sectors are dealing with extreme volatility and economic uncertainty. Even as the dislocation caused by the pandemic three years ago looked to be settling down, business leaders have had to contend with geopolitical concerns, rising interest rates, and surging inflation.…

☐ β˜† βœ‡ The Register - Security

MSI hit in cyberattack, warns against installing knock-off firmware

April 7th 2023 at 23:26

1.5TB of databases, source code, BIOS tools said to be stolen

Owners of MSI-brand motherboards, GPUs, notebooks, PCs, and other equipment should exercise caution when updating their device's firmware or BIOS after the manufacturer revealed it has recently suffered a cyberattack.…

☐ β˜† βœ‡ The Register - Security

Welcome to open source, Elon. Your Twitter code just got a CVE for shadow ban bug

April 7th 2023 at 19:12

Plus: Substack shanked by bitter Twitter?

The chunk of internal source code Twitter released the other week contains a "shadow ban" vulnerability serious enough to earn its own CVE, as it can be exploited to bury someone's account of sight "without recourse."…

☐ β˜† βœ‡ The Register - Security

It's this easy to seize control of someone's Nexx 'smart' home plugs, garage doors

April 7th 2023 at 11:00

Netizens urged to disconnect kit after 40,000-plus devices found riddled with dumb bugs

A handful of bugs in Nexx's smart home devices can be exploited by crooks to, among other things, open doors, power off appliances, and disable alarms. More than 40,000 of these gadgets in residential and commercial properties are said to be vulnerable after the manufacturer failed to act.…

☐ β˜† βœ‡ The Register - Security

With ICMP magic, you can snoop on vulnerable HiSilicon, Qualcomm-powered Wi-Fi

April 7th 2023 at 07:30

WPA stands for will-provide-access, if you can successfully exploit a target's setup

A vulnerability identified in at least 55 Wi-Fi router models can be exploited by miscreants to spy on victims' data as it's sent over a wireless network.…

☐ β˜† βœ‡ The Register - Security

CAN do attitude: How thieves steal cars using network bus

April 6th 2023 at 10:34

It starts with a headlamp and fake smart speaker, and ends in an injection attack and a vanished motor

Automotive security experts say they have uncovered a method of car theft relying on direct access to the vehicle's system bus via a smart headlamp's wiring.…

☐ β˜† βœ‡ The Register - Security

Criminal records office yanks web portal offline amid 'cyber security incident'

April 6th 2023 at 08:30

ACRO says payment data safe, other info may have been snaffled

ACRO, the UK's criminal records office, is combing over a "cyber security incident" that forced it to pull its customer portal offline.…

☐ β˜† βœ‡ The Register - Security

Cops cuff teenage 'Robin Hood hacker' suspected of peddling stolen info

April 6th 2023 at 07:33

Luxury cars and designer duds don't seem very prince of thieves

Spanish cops have arrested a 19-year-old suspected of stealing records belonging to half a million taxpayers and developing a database to sell stolen information to other cyber criminals.…

☐ β˜† βœ‡ The Register - Security

Cops put the squeeze on Genesis crime souk denizens, not just the admins this time

April 5th 2023 at 21:45

Feds managed to image entire backend server with full details

The FBI today released additional information about its takedown of the Genesis Market, a major online shop for stolen account access credentials, revealing that they'd pwned the marketplace for at least two years.…

☐ β˜† βœ‡ The Register - Security

Microsoft tells admins to autoreview your Autopatch alerts or autolose the service

April 5th 2023 at 11:15

And you wouldn't want that ... would you?

Microsoft is updating a service introduced last year that shifts the responsibility of patching Windows devices from IT admins to the vendor itself.…

☐ β˜† βœ‡ The Register - Security

Notorious stolen credential warehouse Genesis Market seized by FBI

April 5th 2023 at 06:30

Operation Cookie Monster crumbles stolen data-as-a-service vendor

A notorious source of stolen credentials, genesis.market, has had its website seized by the FBI.…

☐ β˜† βœ‡ The Register - Security

Feds seize $112m in cryptocurrency linked to 'pig-butchering' finance scams

April 4th 2023 at 23:00

Thieves go nose-to-tail stripping cash from victims

The US Department of Justice has seized cryptocurrency worth about $112 million from accounts linked to so-called pig butchering investment scams.…

☐ β˜† βœ‡ The Register - Security

Can ChatGPT bash together some data-stealing code? With the right prompts, sure

April 4th 2023 at 22:00

But nothing a keen beginner couldn't do, anyway

A Forcepoint staffer has blogged about how he used ChatGPT to craft some code that exfiltrates data from an infected machine. At first, it sounds bad, but in reality, it's nothing an intermediate or keen beginner programmer couldn't whack together themselves anyway.…

☐ β˜† βœ‡ The Register - Security

UK data watchdog fines TikTok Β£12.7M for failing to protect kids

April 4th 2023 at 13:42

Some 1.4 million under-13s used the app in 2020 by the ICO's estimates

Fresh off the back of an embarrassing "grilling" by US Congress on national security grounds, TikTok has received a more concrete reprimand from the UK's Information Commissioner's Office (ICO) – a fine of Β£12.7 million ($15.8 million) for "misusing children's data."…

☐ β˜† βœ‡ The Register - Security

Bank rewrote ads for infosec jobs to stop scaring away women

April 4th 2023 at 05:37

Blokes happily bluffed; women played it by the book, leaving the bank struggling to hire

Australia's Westpac bank re-wrote its job ads for infosec roles after finding the language it used deterred female candidates.…

☐ β˜† βœ‡ The Register - Security

Hey Siri, use this ultrasound attack to disarm a smart-home system

April 4th 2023 at 00:59

We speak to the boffins behind latest trick to fool Google Assistant, Cortana, Alexa

Academics in the US have developed an attack dubbed NUIT, for Near-Ultrasound Inaudible Trojan, that exploits vulnerabilities in smart device microphones and voice assistants to silently and remotely access smart phones and home devices.…

☐ β˜† βœ‡ The Register - Security

Uber driver info stolen yet again: This time from law firm

April 3rd 2023 at 20:27

Never mind software supply chain attacks, lawyers are the new soft target?

Uber has had more of its internal data stolen from a third party that suffered a security breach. This time, the personal info of the app's drivers was swiped by miscreants from the IT systems of law firm Genova Burns.…

☐ β˜† βœ‡ The Register - Security

April brings tulips, taxes ... and phisherfolk scammers

April 3rd 2023 at 18:39

Tactical#Octopus: Don't let users click on that zip file

The last few days of America's tax season are stressful enough, dealing with deadlines and, increasingly, online scams. Now comes another one, a sophisticated and ongoing phishing campaign by a threat group dubbed "Tactical#Octopus" that is using tax-related lures to spread malware.…

☐ β˜† βœ‡ The Register - Security

Capita: Cyber-attack broke some of our IT systems

April 3rd 2023 at 15:33

Staff regain access to Microsoft apps, tech outsourcer still working to restore services for some

Capita – everyone's favorite outsourcing badass – is still working to restore services for some customers after admitting the IT outage of certain services on Friday was caused by a cyber attack and efforts to contain the infiltration.…

☐ β˜† βœ‡ The Register - Security

Keeping secrets safe

April 3rd 2023 at 13:22

How to implement robust secret and identity management

Webinar Keeping digital authentication credentials safe is a highly sensitive task in an ever-evolving IT landscape, made more difficult when you consider the ongoing shift from static to dynamic applications aligned with increasingly distributed teams of workers.…

☐ β˜† βœ‡ The Register - Security

Western Digital confirms digital burglary, calls the cops

April 3rd 2023 at 11:58

Thinks info from internal systems 'obtained' by miscreant, unsure of nature or scope data

Western Digital is today dealing with a "network security incident" after detecting a break-in into its internal systems by an unauthorized third party.…

☐ β˜† βœ‡ The Register - Security

3CX thought supply chain attack was a false positive

April 3rd 2023 at 07:32

'It's not unusual for VoIP apps' says CEO

Updated The CEO of VoIP software provider 3CX said his team tested its products in response to alerts of suspicious activity that was later found to be a supply chain attack, and assessed reports of issues with the software as a false positive.…

☐ β˜† βœ‡ The Register - Security

Vietnam threatens to cut off two million mobile subscribers

April 3rd 2023 at 04:33

To scupper scams, account-holders must hand over personal info or else

Almost two million mobile phone subscribers in Vietnam are at risk of having their services severed, thanks to a new government policy that seeks to curb spam.…

☐ β˜† βœ‡ The Register - Security

School principal resigns after writing $100,000 check to Elon Musk impersonator

April 3rd 2023 at 01:58

ALSO: DJI forgets the 'B' in 'BCC,' and this week's critical known exploits

In Brief The principal of a Florida science and technology charter school has resigned after allegedly writing a $100,000 check to an Elon Musk impersonator using school funds.…

☐ β˜† βœ‡ The Register - Security

Ukrainian cops nab suspects accused of stealing $4.3m from victims across Europe

April 1st 2023 at 07:25

If the price looks too good to be true, it probably is

Ukrainian cops have arrested two suspects and detained 10 others for their alleged roles in a cybercrime gang that used phishing scams and phony online marketplaces to steal more than $4.3 million from over 1,000 victims across Europe.…

☐ β˜† βœ‡ The Register - Security

NYPD blues: Cops ignored 93 percent of surveillance law rules

March 31st 2023 at 20:06

Who watches the watchmen? The Office of the Inspector General

Back in July 2020, then New York City Mayor Bill de Blasio signed the Public Oversight of Surveillance Technology (POST) Act into law, which required the New York Police Department to reveal how it uses surveillance technology and to formulate surveillance policies.…

☐ β˜† βœ‡ The Register - Security

Psst! Infosec bigwigs: Wanna be head of security at HM Treasury for Β£50k?

March 31st 2023 at 11:40

Juicy private sector job vs … money off a season travel ticket

Given the importance of the Treasury department's function to Britain, Reg readers might expect the Head of Cyber Security vacancy currently being advertised would come with a salary that reflects its criticality.…

☐ β˜† βœ‡ The Register - Security

NHS Highland 'reprimanded' by data watchdog for BCC blunder with HIV patients

March 31st 2023 at 09:35

'Serious breach of trust' says ICO, 'stakes too high' for mistakes in cases like this

In a classic email snafu NHS Highland sent messages to 37 patients infected with HIV and inadvertently used carbon copy (CC) instead of Blind Carbon Copy meaning the recipients could see each other’s email addresses.…

☐ β˜† βœ‡ The Register - Security

Pro-Russia cyber gang Winter Vivern puts US, Euro lawmakers in line of fire

March 31st 2023 at 07:30

Winter is coming for NATO countries

A cyber spy gang supporting Russia is targeting US elected officials and their staffers, in addition to European lawmakers, using unpatched Zimbra Collaboration software in two campaigns spotted by Proofpoint.…

☐ β˜† βœ‡ The Register - Security

Leaked IT contractor files detail Kremlin's stockpile of cyber-weapons

March 31st 2023 at 01:24

Snowden-esque 'Vulkan' dossier links Moscow firm to FSB, GRU, SRV

An unidentified whistleblower has provided several media organizations with access to leaked documents from NTC Vulkan – a Moscow IT consultancy – that allegedly show how the firm supports Russia's military and intelligence agencies with cyber warfare tools.…

☐ β˜† βœ‡ The Register - Security

Azure blunder left Bing results editable, MS 365 accounts potentially exposed

March 30th 2023 at 23:30

'BingBang' boo-boo affected other internal Microsoft apps, too

An Azure Active Directory (AAD) misconfiguration by Microsoft in one of its own cloud-hosted applications could have allowed miscreants to subvert the IT giant's Bing search engine – even changing search results.…

☐ β˜† βœ‡ The Register - Security

AlienFox malware caught in the cloud hen house

March 30th 2023 at 21:30

Malicious toolkit targets misconfigured hosts in AWS and Office 365

A fast-evolving toolkit that can be used to compromise email and web hosting services represents a disturbing evolution of attacks in the cloud, which for the most part have previously been confined to mining cryptocurrencies.…

☐ β˜† βœ‡ The Register - Security

Do you use comms software from 3CX? What to do next after biz hit in supply chain attack

March 30th 2023 at 16:25

Miscreants hit downstream customers with infostealers

Two security firms have found what they believe to be a supply chain attack on communications software maker 3CX – and the vendor's boss is advising users to switch to the progressive web app until the 3CX desktop client is updated.…

☐ β˜† βœ‡ The Register - Security

Microsoft uses carrot and stick with Exchange Online admins

March 30th 2023 at 14:27

If you need extra time to dump RPS, OK, but email from unsupported Exchange servers is blocked till they’re up to date

Some Exchange Online users who have the RPS feature turned off by Microsoft can now have it re-enabled – at least until September when the tool is retired.…

☐ β˜† βœ‡ The Register - Security

The most important email conversation you will ever have

March 30th 2023 at 09:14

Securing your business against BEC

Webinar Business email compromise (BEC) is possibly the worst of cybercrimes because it abuses trust. It feeds on relationships carefully nurtured over decades and erodes a confidence which is foundational to cooperation, and progress.…

☐ β˜† βœ‡ The Register - Security

Warning: Your wireless networks may leak data thanks to Wi-Fi spec ambiguity

March 30th 2023 at 06:29

How someone can nab buffered info, by hook or by kr00k

Ambiguity in the Wi-Fi specification has left the wireless networking stacks in various operating systems vulnerable to several attacks that have the potential to expose network traffic.…

☐ β˜† βœ‡ The Register - Security

Another year, another North Korean malware-spreading, crypto-stealing gang named

March 30th 2023 at 04:40

Mandiant identifies 'moderately sophisticated' but 'prolific' APT43 as global menace

Google Cloud's recently acquired security outfit Mandiant has named a new nasty from North Korea: a cyber crime gang it calls APT43 and accuses of a five-year rampage.…

☐ β˜† βœ‡ The Register - Security

Smugglers busted sneaking tech into China

March 30th 2023 at 03:02

'Intel inside' a suspiciously baggy t-shirt gave the game away – as did a truckload of parts

International Talk Like a Pirate Day is still months away – circle September 19 on your calendar, me hearties! – but The Register has found news of technology smuggling in China that suggests a buccaneering approach to imports.…

☐ β˜† βœ‡ The Register - Security

Malware disguised as Tor browser steals $400k in cryptocash

March 30th 2023 at 01:30

Beware of third party downloads

Clipboard-injector malware disguised as Tor browser installers has been used to steal about $400,000 in cryptocurrency from nearly 16,000 users worldwide so far in 2023, according to Kaspersky researchers.…

☐ β˜† βœ‡ The Register - Security

Microsoft Defender shoots down legit URLs as malicious

March 29th 2023 at 18:31

Those hoping to use nefarious websites like, er, Zoom are overrun by alerts. Redmond 'investigating'

Updated Microsoft's at-times-glitchy Defender service is again causing headaches for IT admins by flagging legitimate URLs as malicious.…

☐ β˜† βœ‡ The Register - Security

EU mandated messaging platform love-in is easier said than done: Cambridge boffins

March 29th 2023 at 14:28

Digital Market Act interoperability requirement a social challenge as well as a technical one

By March 2024, instant messaging and real-time media apps operated by large tech platforms in Europe will be required to communicate with other services, per the EU's Digital Markets Act (DMA).…

☐ β˜† βœ‡ The Register - Security

FTX cryptovillain Sam Bankman-Fried charged with bribing Chinese officials

March 29th 2023 at 10:24

Court gives him new rules: Use one laptop, while living with the 'rents.

US authorities have charged FTX co-founder Sam Bankman-Fried (aka SBF) with attempting to bribe Chinese officials with $40 million worth of cryptocurrency in exchange for unfreezing trading accounts.…

☐ β˜† βœ‡ The Register - Security

DDoS DNS attacks are old-school, unsophisticated … and they’re back

March 29th 2023 at 08:34

So why would you handle them on your own?

Sponsored Feature Ransomware may currently be the biggest bogeyman for cybersecurity pros, law enforcement, and governments, but it shouldn't divert us from more traditional, but still very disruptive threats.…

☐ β˜† βœ‡ The Register - Security

China urges Apple to improve security and privacy

March 29th 2023 at 01:27

It's a juicy market that welcomes foreign investment, National development boss reminds Tim Cook

Senior Chinese government officials have urged Apple CEO Tim Cook to improve the security and privacy features of his company's products.…

☐ β˜† βœ‡ The Register - Security

Apple patches all the iThings, including iOS 15 hole under attack right now

March 28th 2023 at 22:16

Issue identified in February but owners of older kit weren't warned

Happy belated Patch Tuesday from Cupertino: Apple has issued security updates for almost every piece of code it slings - including a fix for a vulnerability in older iOS devices the iGiant believes is under attack right now.…

☐ β˜† βœ‡ The Register - Security

Google again accused of willfully destroying evidence in Android antitrust battle

March 28th 2023 at 20:09

Starting to see a pattern here? Judge seems to think so

Updated Google Chat histories handed over by the web giant in ongoing Android antitrust litigation reveal the biz has been systematically destroying evidence, according to those suing the big G.…

☐ β˜† βœ‡ The Register - Security

President Biden kind of mostly bans commercial spyware from US govt

March 28th 2023 at 02:45

Executive order has loopholes for Uncle Sam's snoop tools and American-made code

US president Joe Biden on Monday issued an executive order on the "prohibition on use by the United States government of commercial spyware that poses risks to national security" – a title that is not quite as simple it seems.…

☐ β˜† βœ‡ The Register - Security

Lawyers cough up $200k after health data stolen in Microsoft Exchange pillaging

March 27th 2023 at 22:45

In addition to $100k given to LockBit

New York law firm Heidell, Pittoni, Murphy and Bach (HPMB) has agreed to pay $200,000 to settle a data-breach lawsuit related to the now-notorious Hafnium Microsoft Exchange attacks that siphoned sensitive data from victims around the world. …

☐ β˜† βœ‡ The Register - Security

Gone in 120 seconds: Tesla Model 3 child's play for hackers

March 27th 2023 at 11:32

Plus OIG finds Uncle Sam fibbed over Login.gov

In brief A team of hackers from French security shop Synacktiv have won $100,000 and a Tesla Model 3 after subverting the Muskmobile's entertainment system, and from there opening up the car's core management systems.…

☐ β˜† βœ‡ The Register - Security

China crisis is a TikToking time bomb

March 27th 2023 at 09:30

ByteDance with the devil if you dare

Opinion As country after country bans TikTok from official systems, it’s fair to ask what’s so dodgy about a social network filled with dance crazes, makeup advice and cats.…

☐ β˜† βœ‡ The Register - Security

CISA unleashes Untitled Goose Tool to honk at danger in Microsoft's cloud

March 24th 2023 at 19:16

Not a headline we expected to write today

American cybersecurity officials have released an early-warning system to protect Microsoft cloud users.…

❌