FreshRSS

πŸ”’
☐ β˜† βœ‡ The Register - Security

Capita has 'evidence' customer data was stolen in digital burglary

April 20th 2023 at 13:29

Admits criminals accessed 4% of servers from March 22 until it spotted them at month-end

Business process outsourcing and tech services player Capita says there is proof that some customer data was scooped up by cyber baddies that broke into its systems late last month.…

☐ β˜† βœ‡ The Register - Security

An earlier supply chain attack led to the 3CX supply chain attack, Mandiant says

April 20th 2023 at 12:00

Threat hunters traced it back to malware-laced Trading Technologies' software

The supply-chain attack against 3CX last month was caused by an earlier supply-chain compromise of a different software firm β€” Trading Technologies β€” according to Mandiant, whose consulting crew was hired by 3CX to help the VoIP biz investigate the intrusion.…

☐ β˜† βœ‡ The Register - Security

AI defenders ready to foil AI-armed attackers

April 20th 2023 at 08:34

Operational AI cybersecurity systems have been gaining valuable experience that will enable them to defend against AI-armed opponents.

Sponsored Feature For some time now, alerts concerning the utilisation of AI by cybercriminals have been sounded in specialist and mainstream media alike – with the set-to between AI-armed attackers and AI-protected defenders envisaged in vivid gladiatorial terms.…

☐ β˜† βœ‡ The Register - Security

Protect the Industrial Control Systems (ICS)

April 20th 2023 at 08:08

ICS security is fast becoming a frontline defense against hackers intent on causing mayhem

Sponsored Post Some of the most famous cyber attacks in history have been directed against Industrial Control Systems (ICS).…

☐ β˜† βœ‡ The Register - Security

Medusa ransomware crew brags about spreading Bing, Cortana source code

April 19th 2023 at 23:12

'Does have a somewhat Lapsus$ish feel' we're told

The Medusa ransomware gang has put online what it claims is a massive leak of internal Microsoft materials, including Bing and Cortana source code.…

☐ β˜† βœ‡ The Register - Security

Appeals court spares Google from $20m patent payout over Chrome

April 19th 2023 at 22:28

Chocolate Factory can afford some staples now, or?

Six years after a jury decided otherwise, Google has convinced an appeals court to reverse a $20 million patent judgment against the web giant.…

☐ β˜† βœ‡ The Register - Security

Spyware slinger QuaDream’s reported demise may be the canary in the coal mine

April 19th 2023 at 20:20

NSO and others are still out there, but pariahs find it hard to do business

Analysis Israeli spyware shop QuaDream is reportedly shutting down due to financial troubles.…

☐ β˜† βœ‡ The Register - Security

GitHub debuts pedigree check for npm packages via Actions

April 19th 2023 at 16:00

Publishing provenance possibly prevents problems

Developers who use GitHub Actions to build software packages for the npm registry can now add a command flag that will publish details about the code's origin.…

☐ β˜† βœ‡ The Register - Security

Prioritize what matters most

April 19th 2023 at 09:34

How to manage your cloud and container vulnerabilities at scale

Webinar There's nothing complicated about the statistics released in Sysdig's latest report. They're alarming and should keep many an IT team up at night.…

☐ β˜† βœ‡ The Register - Security

US citizens charged with pushing pro-Kremlin disinfo, election interference

April 18th 2023 at 23:35

Also a bunch of Russians plus someone giving free trips to the Motherland

Four US citizens have been accused of working on behalf of the Russian government to push pro-Kremlin propaganda and unduly influence elections in Florida.…

☐ β˜† βœ‡ The Register - Security

Russian snoops just love invading unpatched Cisco gear, America and UK warn

April 18th 2023 at 20:45

Spying on foreign targets? That's our job!

The UK and US governments have sounded the alarm on Russian intelligence targeting unpatched Cisco routers to deploy malware and carry out surveillance.…

☐ β˜† βœ‡ The Register - Security

Microsoft opens up Defender threat intel library with file hash, URL search

April 18th 2023 at 19:30

Surprised there's no ChatGPT angle and that it's not called MalwareTotal

Security researchers and analysts can now search Microsoft's Threat Intelligence Defender database using file hashes and URLs when pulling together information for network intrusion investigations and whatnot.…

☐ β˜† βœ‡ The Register - Security

Payments firm accused of aiding 'contact Microsoft about a virus' scammers must cough $650k

April 18th 2023 at 18:34

'My computer locked up and a siren went off,' one mark tells Better Business Bureau

Updated Two execs and a multinational payment processing company must pay $650k to the US government, says the FTC, which accuses them of knowingly processing credit card payments for Microsoft-themed support scammers.…

☐ β˜† βœ‡ The Register - Security

Brit cops rapped over app that recorded 200k phone calls

April 18th 2023 at 13:38

Officers didn't know software was saving personal data and neither did people on other end

Several police forces in Britain are being put on the naughty step by the UK's data watchdog for using a calling app that recorded hundreds of thousands of phone conversations and illegally retained that data.…

☐ β˜† βœ‡ The Register - Security

Wrong time to weaken encryption, UK IT chartered institute tells government

April 18th 2023 at 11:27

Plus: Signal, WhatsApp, and Viber also write online protest over Online Safety Bill back door

The UK’s chartered institute for IT has slammed proposed legislation that could see the government open a β€œback door” to encrypted messaging.…

☐ β˜† βœ‡ The Register - Security

Capita IT breach gets worse as Black Basta claims it's now selling off stolen data

April 18th 2023 at 07:25

No worries, outsourcer only handles government tech contracts worth billions

Black Basta, the extortionists who claimed they were the ones who lately broke into Capita, have reportedly put up for sale sensitive details, including bank account information, addresses, and passport photos, stolen from the IT outsourcing giant.…

☐ β˜† βœ‡ The Register - Security

US alleges China created troll army that tried to have dissidents booted from Zoom

April 18th 2023 at 04:37

Charges laid against 44, including officers of China’s Cyberspace Administration

The United States Department of Justice has charged 44 people over schemes prosecutors allege were run by China’s National Police to silence opponents of the Communist Party of China.…

☐ β˜† βœ‡ The Register - Security

Military helicopter crash blamed on failure to apply software patch

April 18th 2023 at 03:30

A rather nice beach in Australia now briefly hosted an unusual feature

An Australian military helicopter crash was reportedly caused by failure to apply a software patch, with a hefty side serving of pilot error.…

☐ β˜† βœ‡ The Register - Security

LockBit crew cooks up half-baked Mac ransomware

April 17th 2023 at 21:30

Please, no need to fix these problems

LockBit has developed ransomware that can encrypt files on Arm-powered Macs, said to be a first for the prolific cybercrime crew. …

☐ β˜† βœ‡ The Register - Security

Marketing biz sent 107 million spam emails... to just 437k people

April 17th 2023 at 12:45

Recruitment company fined Β£130,000 by data regulator for breaking PECR

A recruitment business that sent out an eye watering 107 million spam emails is now nursing a Β£130,000 ($161,000) fine from Britain’s data watchdog.…

☐ β˜† βœ‡ The Register - Security

Firmware is on shaky ground – let's see what it's made of

April 17th 2023 at 09:41

Old architectures just don't stack up

Opinion Most data theft does clear harm to the victim, and often to its customers. But while embarrassing, the cyberattack against MSI in which source code was said to be stolen is harder to diagnose. It looks like a valuable company asset that's cost a lot to develop. That its theft may be no loss is a weird idea. But then, firmware is weirder than we give it credit for. It's even hard to say exactly what it is.…

☐ β˜† βœ‡ The Register - Security

Student requested access to research data. And waited. And waited. And then hacked to get root

April 17th 2023 at 07:29

The punishment – Windows 98 administration chores – was far worse than the crime

Who, Me? Welcome once more to Who Me? The Register’s confessional column in which readers admit to being the source of SNAFUs.…

☐ β˜† βœ‡ The Register - Security

Update now: Google emits emergency fix for zero-day Chrome vulnerability

April 17th 2023 at 01:15

Also: Tech players spin up white hat protection, this week's critical bugs, and more

In brief Google on Friday released an emergency update for Chrome to address a zero-day security flaw.…

☐ β˜† βœ‡ The Register - Security

Russia-pushed UN Cybercrime Treaty may rewrite global law. It's ... not great

April 14th 2023 at 23:46

Let's go through all the proposed problematic powers, starting with surveillance and censorship

Special report United Nations negotiators convened this week in Vienna, Austria, to formulate a draft cybercrime treaty, and civil society groups are worried.…

☐ β˜† βœ‡ The Register - Security

US extradites Nigerian charged over $6m email fraud scam

April 14th 2023 at 21:20

Maybe our prince has come at last

A suspected Nigerian fraudster is scheduled to appear in court Friday for his alleged role in a $6 million plot to scam businesses via email.…

☐ β˜† βœ‡ The Register - Security

Compatibility mess breaks not one but two Windows password tools

April 14th 2023 at 17:50

Windows LAPS and legacy LAPS don't play nicely under certain conditions, Microsoft says

Integrating the Local Administrator Password Solution (LAPS) into Windows and Windows Server that came with updates earlier this week is causing interoperability problems with what's called legacy LAPS, Microsoft says.…

☐ β˜† βœ‡ The Register - Security

While Twitter wants to sell its verification, Microsoft will do it for free on LinkedIn

April 14th 2023 at 10:14

Redmond expands a digital ID process for its platform as Musk seeks cash for blue check marks

As Elon Musk tears at Twitter's credibility by demanding businesses and individuals pay for their blue verification checks, Microsoft is pushing its own free digital ID tech to companies and their employees on LinkedIn.…

☐ β˜† βœ‡ The Register - Security

Linux kernel logic allowed Spectre attack on 'major cloud provider'

April 14th 2023 at 06:27

Kernel 6.2 ditched a useful defense against ghostly chip design flaw

The Spectre vulnerability that has haunted hardware and software makers since 2018 continues to defy efforts to bury it.…

☐ β˜† βœ‡ The Register - Security

To improve security, consider how the aviation world stopped blaming pilots

April 14th 2023 at 04:29

When admitting to an error isn't seen as a failure, improvement easy to achieve, says pilot-turned-CISO

To improve security, the cybersecurity industry needs to follow the aviation industry's shift from a blame culture to a "just" culture, according to ISACA director Serge Christiaans.…

☐ β˜† βœ‡ The Register - Security

Pentagon super-leak suspect cuffed: 21-year-old Air National Guardsman

April 13th 2023 at 19:52

When bragging about your job on Discord gets just a little out of hand?

The FBI has detained a 21-year-old Air National Guardsman suspected of leaking a trove of classified Pentagon documents on Discord.…

☐ β˜† βœ‡ The Register - Security

How insecure is America's FirstNet emergency response system? Seriously, anyone know?

April 12th 2023 at 23:58

Senator Wyden warns full probe needed into vital comms network

AT&T is "concealing vital cybersecurity reporting" about its FirstNet phone network for first responders and the US military, according to US Senator Ron Wyden (D-OR), who said the network had been dubbed unsafe by CISA.…

☐ β˜† βœ‡ The Register - Security

FBI: How fake Xi cops prey on Chinese nationals in the US

April 12th 2023 at 23:26

δ½ ε₯½ [insert name], ζˆ‘εœ¨ Ministry of Public Security ε·₯作 [insert shakedown]

Criminals posing as law enforcement agents of the Chinese government are shaking down Chinese nationals living the United States by accusing them of financial crimes and threatening to arrest or hurt them if they don't pay, according to the FBI.…

☐ β˜† βœ‡ The Register - Security

Mission possible

April 12th 2023 at 09:21

Tamping down risk in cloud management

Webinar There's nothing like reading a report based on real world data to give IT teams an fresh sense of priority.…

☐ β˜† βœ‡ The Register - Security

3CX teases security-focused client update, plus password hashing

April 12th 2023 at 04:35

As Mandiant finds more evidence it was North Korea wot done it

The CEO of VoIP software provider 3CX has teased the imminent release of a security-focused upgrade to the company’s progressive web application client.…

☐ β˜† βœ‡ The Register - Security

US cyber chiefs warn AI will help crooks, China develop nastier cyberattacks faster

April 12th 2023 at 01:50

It's not all doom and gloom because ML also amplifies defensive efforts, probably

Bots like ChatGPT may not be able to pull off the next big Microsoft server worm or Colonial Pipeline ransomware super-infection but they may help criminal gangs and nation-state hackers develop some attacks against IT, according to Rob Joyce, director of the NSA's Cybersecurity Directorate.…

☐ β˜† βœ‡ The Register - Security

Another zero-click Apple spyware maker just popped up on the radar again

April 12th 2023 at 00:42

Pegasus, pssh, you so 2000-and-late

Malware reportedly developed by a little-known Israeli commercial spyware maker has been found on devices of journalists, politicians, and an NGO worker in multiple countries, say researchers. …

☐ β˜† βœ‡ The Register - Security

April Patch Tuesday: Ransomware gangs already exploiting this Windows bug

April 11th 2023 at 23:04

Plus Google, SAP, Adobe and Cisco emit fixes

Microsoft patched 97 security flaws today for April's Patch Tuesday including one that has already been found and exploited by miscreants attempting to deploy Nokoyawa ransomware.…

☐ β˜† βœ‡ The Register - Security

Azure admins warned to disable shared key access as backdoor attack detailed

April 11th 2023 at 13:00

The default is that sharing is caring as Redmond admits: 'These permissions could be abused'

A design flaw in Microsoft Azure – that shared key authorization is enabled by default when creating storage accounts – could give attackers full access to your environment, according to Orca Security researchers.…

☐ β˜† βœ‡ The Register - Security

40% of IT security pros say they've been told not to report a data leak

April 11th 2023 at 09:37

Plus: KFC, Pizza Hut owner spills more beans on ransomware hit... latest critical flaws... and more

In Brief More than 40 percent of surveyed IT security professionals say they've been told to keep network breaches under wraps despite laws and common decency requiring disclosure.…

☐ β˜† βœ‡ The Register - Security

How much to infect Android phones via Google Play store? How about $20k

April 10th 2023 at 23:01

Or whatever you managed to haggle with these miscreants

If you want to sneak malware onto people's Android devices via the official Google Play store, it may cost you about $20,000 to do so, Kaspersky suggests.…

☐ β˜† βœ‡ The Register - Security

Inside FTX: Jokes about misplaced funds, diabolical IT, poor oversight, and worse

April 10th 2023 at 21:43

How's the saying go? $50m here, $50m there, pretty soon you're talking real money

The liquidators picking over the remains of FTX have released their first formal report into Sam Bankman-Fried's imploded empire – and it somehow appears things are worse than feared.…

☐ β˜† βœ‡ The Register - Security

Apple squashes iOS, macOS zero-day bugs already exploited by snoops

April 10th 2023 at 21:01

Keep calm and install patches before abuse becomes widespread

Apple rolled out patches on Good Friday to its iOS, iPadOS, and macOS operating systems and the Safari web browser to address vulnerabilities found by Google and Amnesty International that were exploited in the wild.…

☐ β˜† βœ‡ The Register - Security

Google to kill Dropcam, Nest Secure hardware next year

April 10th 2023 at 18:58

Great, more company for Stadia, Duo and pals in the graveyard

Owners of Dropcam security cameras and Nest Secure systems have been given an unwelcome deadline from Google: their smart home products will be shut off April 8 next year.…

☐ β˜† βœ‡ The Register - Security

Microsoft, Fortra are this fed up with cyber-gangs abusing Cobalt Strike

April 10th 2023 at 16:29

Oh, sure, let's play a game of legal and technical whack-a-mole

Microsoft and Fortra are taking legal and technical actions to thwart cyber-criminals from using the latter company's Cobalt Strike software to distribute malware.…

☐ β˜† βœ‡ The Register - Security

When it comes to technology, securing your future means securing your present

April 10th 2023 at 13:58

How to build cyber resiliency in the face of complexity

Sponsored Feature Most economies and business sectors are dealing with extreme volatility and economic uncertainty. Even as the dislocation caused by the pandemic three years ago looked to be settling down, business leaders have had to contend with geopolitical concerns, rising interest rates, and surging inflation.…

☐ β˜† βœ‡ The Register - Security

MSI hit in cyberattack, warns against installing knock-off firmware

April 7th 2023 at 23:26

1.5TB of databases, source code, BIOS tools said to be stolen

Owners of MSI-brand motherboards, GPUs, notebooks, PCs, and other equipment should exercise caution when updating their device's firmware or BIOS after the manufacturer revealed it has recently suffered a cyberattack.…

☐ β˜† βœ‡ The Register - Security

Welcome to open source, Elon. Your Twitter code just got a CVE for shadow ban bug

April 7th 2023 at 19:12

Plus: Substack shanked by bitter Twitter?

The chunk of internal source code Twitter released the other week contains a "shadow ban" vulnerability serious enough to earn its own CVE, as it can be exploited to bury someone's account of sight "without recourse."…

☐ β˜† βœ‡ The Register - Security

It's this easy to seize control of someone's Nexx 'smart' home plugs, garage doors

April 7th 2023 at 11:00

Netizens urged to disconnect kit after 40,000-plus devices found riddled with dumb bugs

A handful of bugs in Nexx's smart home devices can be exploited by crooks to, among other things, open doors, power off appliances, and disable alarms. More than 40,000 of these gadgets in residential and commercial properties are said to be vulnerable after the manufacturer failed to act.…

☐ β˜† βœ‡ The Register - Security

With ICMP magic, you can snoop on vulnerable HiSilicon, Qualcomm-powered Wi-Fi

April 7th 2023 at 07:30

WPA stands for will-provide-access, if you can successfully exploit a target's setup

A vulnerability identified in at least 55 Wi-Fi router models can be exploited by miscreants to spy on victims' data as it's sent over a wireless network.…

☐ β˜† βœ‡ The Register - Security

CAN do attitude: How thieves steal cars using network bus

April 6th 2023 at 10:34

It starts with a headlamp and fake smart speaker, and ends in an injection attack and a vanished motor

Automotive security experts say they have uncovered a method of car theft relying on direct access to the vehicle's system bus via a smart headlamp's wiring.…

☐ β˜† βœ‡ The Register - Security

Criminal records office yanks web portal offline amid 'cyber security incident'

April 6th 2023 at 08:30

ACRO says payment data safe, other info may have been snaffled

ACRO, the UK's criminal records office, is combing over a "cyber security incident" that forced it to pull its customer portal offline.…

☐ β˜† βœ‡ The Register - Security

Cops cuff teenage 'Robin Hood hacker' suspected of peddling stolen info

April 6th 2023 at 07:33

Luxury cars and designer duds don't seem very prince of thieves

Spanish cops have arrested a 19-year-old suspected of stealing records belonging to half a million taxpayers and developing a database to sell stolen information to other cyber criminals.…

☐ β˜† βœ‡ The Register - Security

Cops put the squeeze on Genesis crime souk denizens, not just the admins this time

April 5th 2023 at 21:45

Feds managed to image entire backend server with full details

The FBI today released additional information about its takedown of the Genesis Market, a major online shop for stolen account access credentials, revealing that they'd pwned the marketplace for at least two years.…

☐ β˜† βœ‡ The Register - Security

Microsoft tells admins to autoreview your Autopatch alerts or autolose the service

April 5th 2023 at 11:15

And you wouldn't want that ... would you?

Microsoft is updating a service introduced last year that shifts the responsibility of patching Windows devices from IT admins to the vendor itself.…

☐ β˜† βœ‡ The Register - Security

Notorious stolen credential warehouse Genesis Market seized by FBI

April 5th 2023 at 06:30

Operation Cookie Monster crumbles stolen data-as-a-service vendor

A notorious source of stolen credentials, genesis.market, has had its website seized by the FBI.…

☐ β˜† βœ‡ The Register - Security

Feds seize $112m in cryptocurrency linked to 'pig-butchering' finance scams

April 4th 2023 at 23:00

Thieves go nose-to-tail stripping cash from victims

The US Department of Justice has seized cryptocurrency worth about $112 million from accounts linked to so-called pig butchering investment scams.…

☐ β˜† βœ‡ The Register - Security

Can ChatGPT bash together some data-stealing code? With the right prompts, sure

April 4th 2023 at 22:00

But nothing a keen beginner couldn't do, anyway

A Forcepoint staffer has blogged about how he used ChatGPT to craft some code that exfiltrates data from an infected machine. At first, it sounds bad, but in reality, it's nothing an intermediate or keen beginner programmer couldn't whack together themselves anyway.…

☐ β˜† βœ‡ The Register - Security

UK data watchdog fines TikTok Β£12.7M for failing to protect kids

April 4th 2023 at 13:42

Some 1.4 million under-13s used the app in 2020 by the ICO's estimates

Fresh off the back of an embarrassing "grilling" by US Congress on national security grounds, TikTok has received a more concrete reprimand from the UK's Information Commissioner's Office (ICO) – a fine of Β£12.7 million ($15.8 million) for "misusing children's data."…

☐ β˜† βœ‡ The Register - Security

Bank rewrote ads for infosec jobs to stop scaring away women

April 4th 2023 at 05:37

Blokes happily bluffed; women played it by the book, leaving the bank struggling to hire

Australia's Westpac bank re-wrote its job ads for infosec roles after finding the language it used deterred female candidates.…

☐ β˜† βœ‡ The Register - Security

Hey Siri, use this ultrasound attack to disarm a smart-home system

April 4th 2023 at 00:59

We speak to the boffins behind latest trick to fool Google Assistant, Cortana, Alexa

Academics in the US have developed an attack dubbed NUIT, for Near-Ultrasound Inaudible Trojan, that exploits vulnerabilities in smart device microphones and voice assistants to silently and remotely access smart phones and home devices.…

❌