FreshRSS

πŸ”’
☐ β˜† βœ‡ The Register - Security

New York City latest to sue Hyundai and Kia claiming their cars are too easy to steal

June 8th 2023 at 14:32

What started as a TikTok craze has become a 'public nuisance'

Hyundai and Kia cars were stolen 977 times in New York City in the first four months of 2023, and authorities have had enough.…

☐ β˜† βœ‡ The Register - Security

On the frontline of cyber threats

June 8th 2023 at 13:00

Watch it here: the unvarnished truth about the state of data security

Webinar Rubrik Zero Lab's annual report on the state of data security is not a comfortable read. And as if to prepare you for what lies inside, the company has called it 'The Hard Truths.'…

☐ β˜† βœ‡ The Register - Security

Microsoft says share the wealth with cyber-info for business

June 8th 2023 at 09:30

It's better to take action than wait for attacks

The timeworn adage that "those who don't learn from history are doomed to repeat it" can certainly be applied to cyber security. Microsoft is hoping to spare enterprises that use its cloud services from repeating history by sharing what it has learned.…

☐ β˜† βœ‡ The Register - Security

Helping Windows 11 fight the hackers

June 8th 2023 at 09:07

How Intel is using hardware-assisted security to beef up Microsoft OS protection

Sponsored Feature When Windows 11 launched in October 2021, one of its big selling points was a new security architecture. Microsoft designed it from the ground up with zero-trust principles in mind, refusing to trust the legitimacy of any single system component. Instead, everything must prove that it has not been compromised.…

☐ β˜† βœ‡ The Register - Security

UK government to set deadline for removal of Chinese surveillance cams

June 8th 2023 at 07:30

And compile a list of vendors considered threats to national security

The UK government will set a deadline for removing made-in-China surveillance cameras from "sensitive sites."…

☐ β˜† βœ‡ The Register - Security

Deepfakes being used in 'sextortion' scams, FBI warns

June 8th 2023 at 00:45

AI technology raises the bar in an already troubling crime

Miscreants are using AI to create faked images of a sexual nature, which they then employ in sextortion schemes.…

☐ β˜† βœ‡ The Register - Security

Clop ransomware crew sets June extortion deadline for MOVEit victims

June 7th 2023 at 19:46

Plus: The Feds weigh in with advice, details

Clop, the ransomware crew that has exploited the MOVEit vulnerability extensively to steal corporate data, has given victims a June 14 deadline to pay up or the purloined information will be leaked.…

☐ β˜† βœ‡ The Register - Security

10 years after Snowden's first leak, what have we learned?

June 7th 2023 at 13:25

Spies gonna spy

Feature The world got a first glimpse into the US government's far-reaching surveillance of American citizens' communications – namely, their Verizon telephone calls – 10 years ago this week when Edward Snowden's initial leaks hit the press.…

☐ β˜† βœ‡ The Register - Security

Police use of PayPal records under fire after raid on 'Cop City' protest fund trio

June 6th 2023 at 23:03

Nearly anything can look like money laundering if you squint hard enough

Three supporters of activists against a $90 million police training facility dubbed Cop City were arrested after the cops used PayPal data to bring money-laundering charges against the trio.…

☐ β˜† βœ‡ The Register - Security

Malwarebytes may not be allowed to label rival's app as 'potentially unwanted'

June 6th 2023 at 19:56

Legal prof warns: 'This case is like a wrecking ball for internet law'

The US Ninth Circuit Court of Appeals last week ruled that Enigma Software Group can pursue its long standing complaint against rival security firm Malwarebytes for classifying its software as "potentially unwanted programs" or PUPs.…

☐ β˜† βœ‡ The Register - Security

US govt now bans TikTok from contractors' work gear

June 6th 2023 at 19:25

BYODALAINGTI (as long as it's not got TikTok installed)

The US federal government's ban on TikTok has been extended to include devices used by its many contractors - even those that are privately owned. The bottom line: if some electronics are used for government work, it better not have any ByteDance bits on it. …

☐ β˜† βœ‡ The Register - Security

Microsoft cops $20M slap on the wrist for mishandling kids' Xbox data

June 6th 2023 at 18:24

Pocket change, in other words

Microsoft is being fined $20 million by the US Federal Trade Commission for violating the Children's Online Privacy Protection Act (COPPA) by illegally gathering kids' personal information and retaining it without parental consent.…

☐ β˜† βœ‡ The Register - Security

Identity thieves can hunt us for 'rest of our lives,' claims suit after university data leak

June 6th 2023 at 17:34

Crooks steal Social Security numbers and post them on dark web, victims blame holes in Mercer's security

An American university founded in 1833 is facing a bunch of class action lawsuits after the personal data of nearly 100,000 people was stolen from its tech infrastructure.…

☐ β˜† βœ‡ The Register - Security

SEC drops 42 cases after staff bungle data protection

June 6th 2023 at 04:02

Corporate watchdog fouled its info-separation regime, let the wrong people read sensitive docs

The US Securities and Exchange Commission (SEC) has dismissed proceedings against 42 companies and individuals after admitting that its enforcement staff accessed documents that were supposed to be for judges' eyes only.…

☐ β˜† βœ‡ The Register - Security

Microsoft stashes nearly half a billion in case LinkedIn data drama hits

June 2nd 2023 at 15:28

Irish regulators sniffing around Facebook-for-suits subsidiary have threatened fine

Microsoft has warned investors about a "non-public" draft decision by Irish regulators against LinkedIn for allegedly dodgy ad data practices, explaining it had set aside some cash to pay off any potential fine.…

☐ β˜† βœ‡ The Register - Security

Taking the art of email security to the next level

June 6th 2023 at 08:28

AI is beefing up the cyber arsenals of both attackers and defenders

Sponsored Feature Email is a popular target for cybercriminals, offering an easy way of launching an attack disguised as an innocent message. One moment of inattention on the part of the recipient and the door is open to malware, spam, phishing, perhaps even a dose of the dreaded ransomware. Entire organisations can suffer, not just individual victims.…

☐ β˜† βœ‡ The Register - Security

British Airways, Boots, BBC payroll data stolen in MOVEit supply-chain attack

June 5th 2023 at 19:29

Microsoft blames Russian Clop ransomware crew for theft of staff info

British Airways, the BBC, and UK pharmacy chain Boots are among the companies whose data has been compromised after miscreants exploited a critical vulnerability in deployments of the MOVEit document-transfer app.…

☐ β˜† βœ‡ The Register - Security

Crypto catastrophe strikes some Atomic Wallet users, over $35M thought stolen

June 5th 2023 at 18:31

Victims nursing huge losses haven't the foggiest how heist happened, yet

As much as $35 million worth of cryptocurrency may have been stolen in a large-scale attack on Atomic Wallet users, with one investigator claiming losses could potentially exceed $50 million.…

☐ β˜† βœ‡ The Register - Security

Qbot malware adapts to live another day … and another …

June 5th 2023 at 12:15

Operators stay ahead of defenders with new access methods and C2 infrastructure

The Qbot malware operation – which started more than a decade ago as banking trojan only to evolve into a backdoor and a delivery system for ransomware and other threats – continues to deftly adapt its techniques to stay ahead of security pros, according to a new report.…

☐ β˜† βœ‡ The Register - Security

Australian cyber-op attacked ISIL with the terrifying power of Rickrolling

June 5th 2023 at 04:29

Commanders in the field persuaded to give up, let their guard down, run around and desert their posts

Australia's Signals Directorate, the signals intelligence organization, has revealed it employed zero-click attacks on devices used by fighters for Islamic State of Iraq and the Levant (ISIL) – then unleashed the terrifying power of Rick Astley.…

☐ β˜† βœ‡ The Register - Security

Toyota admits to yet another cloud leak

June 5th 2023 at 03:30

Also, hackers publish RaidForum user data, Google's $180k Chrome bug bounty, and this week's vulnerabilities

infosec in brief Japanese automaker Toyota is again apologizing for spilling customer records online due to a misconfigured cloud environment – the same explanation it gave when the same thing happened a couple of weeks ago. It's like a pattern.…

☐ β˜† βœ‡ The Register - Security

Meet TeamT5, the Taiwanese infosec outfit taking on Beijing and defeating its smears

June 5th 2023 at 02:33

Living in the eye of the geopolitical storm is not easy, but is good for business

In late September 2021, staff at Taiwanese threat intelligence company TeamT5 noticed something very nasty: a fake news report accusing it of conducting phishing attacks against Japan's government and local tech companies.…

☐ β˜† βœ‡ The Register - Security

Uncle Sam wants DEF CON hackers to pwn this Moonlighter satellite in space

June 3rd 2023 at 08:25

'World's first and only' orbiting infosec playpen due to blast off Sunday

Feature Assuming the weather and engineering gods cooperate, a US government-funded satellite dubbed Moonlighter will launch at 1212 EDT (1612 UTC) on Sunday, hitching a ride on a SpaceX rocket before being releasing into Earth's orbit.…

☐ β˜† βœ‡ The Register - Security

Malaysia goes its own Huawei, won't ban Chinese vendor from 5G network

June 2nd 2023 at 18:33

Country to have two networks as first buildout falls behind schedule

Malaysia could be putting itself on a collision course with the EU and US as the country looks set to allow Chinese suppliers including Huawei a chance to play a part in its planned 5G network rollout.…

☐ β˜† βœ‡ The Register - Security

This malicious PyPI package mixed source and compiled code to dodge detection

June 2nd 2023 at 06:24

Oh cool, something else to scan for

Researchers recently uncovered the following novel attack on the Python Package Index (PyPI).…

☐ β˜† βœ‡ The Register - Security

You might have been phished by the gang that stole North Korea’s lousy rocket tech

June 2nd 2023 at 05:15

US, South Korea, warn 'Kimsuky' is a very sophisticated social engineer

The United States and the Republic of Korea have issued a joint cyber security advisory [PDF] about North Koreas "Kimsuky" cyber crime group.…

☐ β˜† βœ‡ The Register - Security

Millions of Gigabyte PC motherboards backdoored? What's the actual score?

June 2nd 2023 at 02:07

It's the 2020s and we're still running code automatically fetched over HTTP

FAQ You may have seen some headlines about a supply-chain backdoor in millions of Gigabyte motherboards. Here's the lowdown.…

☐ β˜† βœ‡ The Register - Security

Deployed publicly accessible MOVEit Transfer? Oh no. Mass exploitation underway

June 1st 2023 at 23:39

Time to MOVEit, MOVEit. We don't like to MOVEit, MOVEit

Security researchers and the US government have sounded the alarm on a flaw in Progress Software's MOVEit Transfer that criminals have been "mass exploiting" for at least a month to break into IT environments and steal data.…

☐ β˜† βœ‡ The Register - Security

Kremlin claims Apple helped NSA spy on diplomats via iPhone backdoor

June 1st 2023 at 21:49

Did we just time warp back to 2013?

Russian intelligence has accused American snoops and Apple of working together to backdoor iPhones to spy on "thousands" of diplomats worldwide.…

☐ β˜† βœ‡ The Register - Security

The downside of frenemies

June 1st 2023 at 16:43

Are DevOps Tools a potential risk to your software supply chain security?

Webinar Popular DevOps tools are great when it comes to helping developers optimize digital infrastructure, but there's a potential downside – the hidden risks they can contain which may compromise your supply chain.…

☐ β˜† βœ‡ The Register - Security

Amazon Ring, Alexa accused of every nightmare IoT security fail you can imagine

June 1st 2023 at 06:33

Staff able to watch customers in the bathroom? Tick! Obviously shabby infosec? Tick! Training AI as an excuse for data retention? Tick!

America's Federal Trade Commission has made Amazon a case study for every cautionary tale about how sloppily designed internet-of-things devices and associated services represent a risk to privacy – and made the cost of those actions, as alleged, a mere $30.8 million.…

☐ β˜† βœ‡ The Register - Security

Ukraine war blurs lines between cyber-crims and state-sponsored attackers

June 1st 2023 at 05:40

This RomCom is no laughing matter

A change in the deployment of the RomCom malware strain has illustrated the blurring distinction between cyberattacks motivated by money and those fueled by geopolitics, in this case Russia's illegal invasion of Ukraine, according to Trend Micro analysts.…

☐ β˜† βœ‡ The Register - Security

Dark Pink cyber-spies add info stealers to their arsenal, notch up more victims

June 1st 2023 at 01:24

Not to be confused with K-Pop sensation BLACKPINK, gang pops military, govt and education orgs

Dark Pink, a suspected nation-state-sponsored cyber-espionage group, has expanded its list of targeted organizations, both geographically and by sector, and has carried out at least two attacks since the beginning of the year.…

☐ β˜† βœ‡ The Register - Security

Feds, you'll need a warrant for that cellphone border search

May 31st 2023 at 23:52

Here's a story with a twist

A federal district judge has ruled that authorities must obtain a warrant to search an American citizen's cellphone at the US border, barring exigent circumstances.…

☐ β˜† βœ‡ The Register - Security

Barracuda Email Security Gateways bitten by data thieves

May 31st 2023 at 18:15

Act now: Sea-themed backdoor malware injected via .tar-based hole

A critical remote command injection vulnerability in some Barracuda Network devices that the vendor patched 11 days ago has been exploited by miscreants – for at least the past seven months.…

☐ β˜† βœ‡ The Register - Security

Criminals spent 10 days in US dental insurer's systems extracting data of 9 million

May 31st 2023 at 17:32

LockBit gang claimed 'trophy' of spilling low income families' details. Their parents must be proud

The criminals who hit one of the biggest government-backed dental care and insurance providers in the US earlier this year hung about for 10 days while they extracted info on nearly 9 million people, including kids from poverty-stricken homes.…

☐ β˜† βœ‡ The Register - Security

XFS bug in Linux kernel 6.3.3 coincides with SGI code comeback

May 31st 2023 at 13:30

G.N.U. Silicon Graphics: a company is not dead while its name is still spoken

SGI may be no more but people are still using its code – and some more of that code may be about to enjoy a revival.…

☐ β˜† βœ‡ The Register - Security

When the popular safeguarding tool is anything but

May 31st 2023 at 13:11

How to stave off software supply chain attacks

Webinar A software supply chain attack is a hugely painful form of infiltration which can paralyse any business or organization. An attack like a lethal snake bite where the poison silently and swiftly infects your whole software base.…

☐ β˜† βœ‡ The Register - Security

Thinking straight in the SoC: How AI erases cognitive bias

May 31st 2023 at 08:59

The whispering voice presents an alternative point of view to steer cyber security pros in the right direction

Sponsored Feature What do bears and cyber criminals have in common? Both of them are scary, and they both have the same effect on security teams.…

☐ β˜† βœ‡ The Register - Security

1. This crypto-coin is called Jimbo. 2. $8m was stolen from its devs in flash loan attack

May 30th 2023 at 23:56

3. It's asked for 90% of the digital dosh back, or else it'll beg the cops for help

Just days after releasing the second – and supposedly more stable and secure – version of its decentralized finance (DeFi) app, Jimbos Protocol over the weekend was hit by attackers who stole stole 4,090 ETH tokens from the project worth about $7.5 million.…

☐ β˜† βœ‡ The Register - Security

90+ orgs tell Slack to stop slacking when it comes to full encryption

May 30th 2023 at 22:53

Protests planned for Wednesday in San Francisco and Denver

A coalition of 90-plus groups, including Fight for the Future and Mozilla, will descend upon Slack's offices in San Francisco and Denver on Wednesday to ask on the collaboration app to protect users' conversations via end-to-end encryption (E2EE).…

☐ β˜† βœ‡ The Register - Security

Pegasus-pusher NSO gets new owner keen on the commercial spyware biz

May 30th 2023 at 19:15

Investors roll the dice against government sanctions and lawsuits

Spyware maker NSO Group has a new ringleader, as the notorious biz seeks to revamp its image amid new reports that the company's Pegasus malware is targeting yet more human rights advocates and journalists.…

☐ β˜† βœ‡ The Register - Security

New York county still dealing with ransomware eight months after attack

May 29th 2023 at 06:30

Also: iSpoof no more, Edmodo fined more than it can pay, UK is #1 (in CC theft), and the week's critical vulns

security in brief The fallout from an eight-month-old cyber attack on a county in Long Island, New York has devolved into mud-slinging as leaders try to figure out just what is going on.…

☐ β˜† βœ‡ The Register - Security

Alien versus Predator? No, this Android spyware works together

May 27th 2023 at 01:23

Phone-hugging code can record calls, read messages, track geolocation, access camera, other snooping

The Android Predator spyware has more surveillance capabilities than previously suspected, according to analysis by Cisco Talos, with an assist from non-profit Citizen Lab in Canada.…

☐ β˜† βœ‡ The Register - Security

US govt pushes spyware to other countries? Senator Wyden would like a word

May 26th 2023 at 21:03

Uncle Sam confirms it's saying nothing

The US International Trade Administration (ITA) has admitted it promotes the sale of American-approved commercial spyware to foreign governments, and won't answer questions about it, according to US Senator Ron Wyden (D-OR).…

☐ β˜† βœ‡ The Register - Security

BlackByte ransomware crew lists city of Augusta after cyber 'incident'

May 26th 2023 at 01:34

Mayor promises to comment on Friday

BlackByte ransomware crew has claimed Augusta, Georgia, as its latest victim, following what the US city's mayor has, so far, only called a cyber "incident."…

☐ β˜† βœ‡ The Register - Security

It's 2023 and Sri Lanka doesn't have a cyber security authority

May 26th 2023 at 00:42

All should change this year as the country passes its Cyber Security Bill

Sri Lanka's Ministry of Technology has confirmed it will have a cyber security authority – at some point.…

☐ β˜† βœ‡ The Register - Security

Spotted: Suspected Russian malware designed to disrupt Euro, Asia energy grids

May 25th 2023 at 21:07

For simulation or for real, we don't like the vibes from this CosmicEnergy

Malware designed to disrupt electric power grids was likely developed by a Russian contractor, according to Mandiant's threat intel team that discovered the malicious software and dubbed it CosmicEnergy.…

☐ β˜† βœ‡ The Register - Security

So the FBI 'persistently' abused its snoop powers. What's to worry about?

May 25th 2023 at 14:30

When is warrantless surveillance warranted?

Register Kettle If there's one thing that's more all the rage these days than this AI hype, it's warrantless spying by the Feds.…

☐ β˜† βœ‡ The Register - Security

Facial recog system used by Met Police shows racial bias at low thresholds

May 25th 2023 at 10:34

Tech used at King's Coronation employs higher thresholds on once-only watch-lists, Met tells MPs

The UK Parliament has heard that a facial recognition system used by the Metropolitan police during the King’s Coronation can exhibit racial bias at certain thresholds.…

☐ β˜† βœ‡ The Register - Security

Five Eyes and Microsoft accuse China of attacking US infrastructure again

May 25th 2023 at 03:30

Defeating Volt Typhoon will be hard, because the attacks look like legit Windows admin activity

China has attacked critical infrastructure organizations in the US using a "living off the land" attack that hides offensive action among everyday Windows admin activity.…

☐ β˜† βœ‡ The Register - Security

This legit Android app turned into mic-snooping malware – and Google missed it

May 24th 2023 at 23:58

File-stealing nasty in my Play store? Preposterous!!1

Google Play has been caught with its cybersecurity pants down yet again after a once-legit Android screen-and-audio recorder app was updated to include malicious code that listened in on device microphones.…

☐ β˜† βœ‡ The Register - Security

Philly Inquirer says Cuba ransomware gang's data leak claims are fake news

May 24th 2023 at 20:26

Now that's a Rocky relationship

The Philadelphia Inquirer has punched back at the Cuba ransomware gang after the criminals leaked what they said were files stolen from the newspaper.…

☐ β˜† βœ‡ The Register - Security

IT security analyst admits hijacking cyber attack to pocket ransom payments

May 24th 2023 at 08:30

Ashley Liles altered blackmail emails in bid to make off with Β£300,000 in Bitcoin

A former IT security analyst at Oxford Biomedica has admitted, five years after the fact, to turning to the dark side – by hijacking a cyber attack against his own company in an attempt to divert any ransom payments to himself.…

☐ β˜† βœ‡ The Register - Security

US bans North Korean outsourcer and its feisty freelancers

May 24th 2023 at 02:58

They do your work – usually from Russia and China – then send their wages home to pay for missiles

When businesses go shopping for IT services, North Korea-controlled companies probably struggle to make it into many lists.…

☐ β˜† βœ‡ The Register - Security

Apria Healthcare says potentially 2M people caught up in IT security breach

May 23rd 2023 at 23:58

Took two years to tell us 'small number of emails' accessed

Personal and financial data describing almost 1.9 million Apria Healthcare patients and employees may have been accessed by crooks who breached the company's networks over a series of months in 2019 and 2021.…

☐ β˜† βœ‡ The Register - Security

Dish confirms 300,000 people's data was exposed in February's attack

May 23rd 2023 at 16:43

But don't worry – we know it was deleted. Hmm. How would you know that?

Dish Network has admitted that a February cybersecurity incident and associated multi-day outage led to the extraction of data on nearly 300,000 people, while also appearing to indirectly admit it may have paid cybercriminals to delete said data.…

☐ β˜† βœ‡ The Register - Security

TikTok to let Oracle view source code, algorithm, and content moderation

May 23rd 2023 at 14:36

It's all in the name of national security as Trump-era collab continues in Project Texas

TikTok, the social video platform used by around 150 million people in the US, is set to hand access to its source code, algorithm and content moderation material to Oracle in a bid to allay data protection and national security concerns stateside.…

☐ β˜† βœ‡ The Register - Security

Ads for lucrative jobs in Asia fail to mention chance of slavery as crypto-scammer

May 23rd 2023 at 05:58

FBI warns jobseekers to be very skeptical of working holidays in Cambodia

The FBI has issued a warning about fake job ads that recruit workers into forced labor operations in Southeast Asia – some of which enslave visitors and force them to participate in cryptocurrency scams.…

☐ β˜† βœ‡ The Register - Security

China hasn't told Micron why it failed security review, or what its ban means

May 23rd 2023 at 02:58

US memory-maker forecasts single-digit revenue impact, and ongoing gloom in PC and smartmobe markets

US memory-maker Micron has no idea why Chinese authorities have decided its products represent a security risk, or which customers it's not allowed to sell to.…

❌