FreshRSS

πŸ”’
☐ β˜† βœ‡ The Register - Security

US government hit by Russia's Clop in MOVEit mass attack

June 15th 2023 at 22:43

CISA chief tells us exploitation 'largely opportunistic', not on same level of SolarWinds

The US Department of Energy and other federal bodies are among a growing list of organizations hit by Russians exploiting the MOVEit file-transfer vulnerability.…

☐ β˜† βœ‡ The Register - Security

Chinese spies blamed for data-harvesting raids on Barracuda email gateways

June 15th 2023 at 18:44

Snoops 'aggressively targeted' specific govt, academic accounts

Chinese spies are behind the data-stealing malware injected into Barracuda's Email Security Gateway (ESG) devices globally as far back as October 2022, according to Mandiant.…

☐ β˜† βœ‡ The Register - Security

North Korea created very phishy evil twin of Naver, South Korea's top portal

June 15th 2023 at 02:15

Think of it as a fake Google tuned for credential capture and you'll understand why authorities want to kill it

North Korea has created a fake version of South Korea's largest internet portal, Naver, in a large scale phishing attempt, Seoul's National Intelligence Service (NIS) said on Wednesday.…

☐ β˜† βœ‡ The Register - Security

Decision to hold women-in-cyber events in abortion-banning states sparks outcry

June 14th 2023 at 23:48

'Many factors were considered,' WiCyS boss tells The Reg as (ISC)Β² suggests an end to 'girlfriend test' jargon

Global nonprofit Women in Cybersecurity (WiCyS), despite months of controversy over the cities named to host its 2024 and 2025 conferences, says it will move forward as planned with the events in Nashville, Tennessee, and Dallas, Texas, respectively.…

☐ β˜† βœ‡ The Register - Security

LockBit victims in the US alone paid over $90m in ransoms since 2020

June 14th 2023 at 19:42

As America, UK, Canada, Australia and friends share essential bible to detect and thwart infections

Seven nations today issued an alert, plus protection tips, about LockBit, the prolific ransomware-as-a-service gang.…

☐ β˜† βœ‡ The Register - Security

Lethal weather

June 14th 2023 at 15:48

Forecasting the flux and flow of threats to the cloud

Webinar The cloud is floating around everywhere and with the rapid expansion of IT always comes new complexities that alter the threat landscape.…

☐ β˜† βœ‡ The Register - Security

Capita wins Β£50M fraud reporting contract with City of London cops

June 14th 2023 at 13:34

No, the irony isn't lost on us either

Capita, which is still dealing with a digital break-in that exposed customers' data to criminals, has scored a Β£50 million contract with the City of London police to run contact and engagement services for the force's fraud reporting service.…

☐ β˜† βœ‡ The Register - Security

Bringing security to account: why identity must be unified

June 14th 2023 at 10:35

As identity management becomes the new security perimeter, cyber risk underwriters want to see resilient IAM control ID sprawl

Sponsored Feature Many organizations are suffering from an identity crisis. Not in the psychological sense, nor in respect to their branding or culture. But in how their IT systems enable employees to access the applications and data they need for work.…

☐ β˜† βœ‡ The Register - Security

Florida man insists he didn't violate the law by keeping Top Secret docs

June 14th 2023 at 00:30

Populist politician pleads not guilty at Miami arraignment

A Florida man and his valet appeared in a Miami federal courtroom on Tuesday to respond to criminal charges of document hoarding and related claims.…

☐ β˜† βœ‡ The Register - Security

June Patch Tuesday: VMware vuln under attack by Chinese spies, Microsoft kinda meh

June 13th 2023 at 20:32

Plus: Adobe, SAP and Android push updates

Microsoft has released security updates for 78 flaws for June's Patch Tuesday, and luckily for admins, none of these are under exploit.…

☐ β˜† βœ‡ The Register - Security

Last of the Gozi 3 sentenced over Windows info-stealing malware ops

June 13th 2023 at 17:33

Banking trojan still going strong as feds put bulletproof hosting point man behind bars

The last of the three men said to be responsible for infecting Windows computers with the banking trojan Gozi has been sentenced to three years.…

☐ β˜† βœ‡ The Register - Security

The commonality of criminal intrusion

June 13th 2023 at 15:07

Rubrik Zero Lab’s β€˜The Hard Truths’ annual report into the state of data security

Webinar It seems no longer possible to imagine whether it's just a case of if a security breach will occur within your organization, or if malicious actors will exploit a vulnerability to play havoc with your data. Rather, it's just a question of when.…

☐ β˜† βœ‡ The Register - Security

These Microsoft Office security signatures are 'practically worthless'

June 13th 2023 at 10:26

Turns out it's easy to forge documents relying on OOXML

Updated Office Open XML (OOXML) Signatures, an Ecma/ISO standard used in Microsoft Office applications and open source OnlyOffice, have several security flaws and can be easily spoofed.…

☐ β˜† βœ‡ The Register - Security

Russia-Ukraine war sending shockwaves into cyber-ecosystem

June 13th 2023 at 08:31

Conflict could be first shooting war to deploy armies of β€˜citizen hackers’ that cause at-risk organisations to rethink their defensive strategies

Sponsored Feature When military historians come to chronicle the first 15 months of the Russian invasion of Ukraine, they won't find any shortage of battlefront bulletins to inform their accounts.…

☐ β˜† βœ‡ The Register - Security

UK telco watchdog Ofcom, Minnesota Dept of Ed named as latest MOVEit victims

June 13th 2023 at 06:28

As another CVE is assigned

Two more organizations hit in the mass exploitation of the MOVEit file-transfer tool have been named – the Minnesota Department of Education in the US, and the UK's telco regulator Ofcom – just days after security researchers discovered additional flaws in Progress Software's buggy suite.…

☐ β˜† βœ‡ The Register - Security

China's cyber now aimed at infrastructure, warns CISA boss

June 13th 2023 at 04:45

Resilience against threats needs a boost

China's cyber-ops against the US have shifted from espionage activities to targeting infrastructure and societal disruption, the director of the Cybersecurity and Infrastructure Security Agency (CISA) Jen Easterly told an Aspen Institute event on Monday.…

☐ β˜† βœ‡ The Register - Security

India probes medical info 'leak' to Telegram

June 13th 2023 at 03:26

PLUS: Vietnam's free domain names for youngsters; China's Cuba spy base; Hyundai and Samsung team for car chips; and more

Asia In Brief India's government has denied its Co-WIN COVID-19 vaccination management platform has leaked data, but ordered an investigation into the program's security.…

☐ β˜† βœ‡ The Register - Security

Unsealed: Charges against Russians blamed for Mt Gox crypto-exchange collapse

June 12th 2023 at 23:23

What a blast from the past, the past being a year before the pandemic

American prosecutors have unsealed an indictment against two Russians who allegedly had a hand in the ransacking and collapse of Mt Gox a decade ago, an implosion that cost the cryptocurrency exchange's thousands of customers most of their digital coins.…

☐ β˜† βœ‡ The Register - Security

Fortinet squashes hijack-my-VPN bug in FortiOS gear

June 12th 2023 at 21:06

And it's already being exploited in the wild, probably

Fortinet has patched a critical bug in its FortiOS and FortiProxy SSL-VPN that can be exploited to hijack the equipment.…

☐ β˜† βœ‡ The Register - Security

Posing as journalists, Pink Drainer pilfers $3.3M in crypto

June 12th 2023 at 20:00

First the interview, then the phishing attack

Miscreants targeting Discord and Twitter accounts have stolen more than $3.3 million in cryptocurrency from 2,300 victims so far in an ongoing campaign that started in April and saw the highest spike in activity earlier this month.…

☐ β˜† βœ‡ The Register - Security

Microsoft stole our stolen dark web data, says security outfit

June 12th 2023 at 19:15

Suit claims Redmond took far more than allowed from Hold's 360M-credential database

Microsoft stands accused by cyber intelligence firm Hold Security of violating an agreement between the pair by misusing Hold's database of more than 360 million sets of credentials culled from the dark web.…

☐ β˜† βœ‡ The Register - Security

Lantum S3 bucket leak is prescription for chaos for thousands of UK doctors

June 12th 2023 at 12:34

Freelance agency exposed personal details that would be highly valuable in the wrong hands

Updated A UK agency for freelance doctors has potentially exposed personal details relating to 3,200 individuals via unsecured S3 buckets, which one expert said could be used to launch ID theft attacks or blackmail.…

☐ β˜† βœ‡ The Register - Security

Hold it – another vulnerability found in MOVEit file transfer software

June 12th 2023 at 10:33

Also, the FBI's $180k investment in AN0M keeps paying off, and this week's critical vulnerabilities

Infosec in brief Security firms helping Progress Software dissect the fallout from a ransomware attack against its MOVEit file transfer suite have discovered an additional exploitable bug.…

☐ β˜† βœ‡ The Register - Security

Online muggers make serious moves on unpatched Microsoft bugs

June 9th 2023 at 23:47

Win32k and Visual Studio flaws are under attack

Two flaws in Microsoft software are under attack on systems that haven't been patched by admins.…

☐ β˜† βœ‡ The Register - Security

FBI: FISA Section 702 'absolutely critical' to spy on, err, protect Americans

June 9th 2023 at 20:30

No protection without surveillance?

The FBI doesn't want to lose its favorite codified way to spy, Section 702 of the US Foreign Intelligence Surveillance Act. In its latest salvo, the agency's deputy director Paul Abbate called it "absolutely critical for the FBI to continue protecting the American people."…

☐ β˜† βœ‡ The Register - Security

Ransomware scum hit Japanese pharma giant Eisai Group

June 9th 2023 at 17:30

Some servers encrypted in weekend attack, but product supply not affected

Japanese pharma giant Eisai today confirmed to The Register that "there is no imminent risk of stock shortage" after it was hit by ransomware at the weekend.…

☐ β˜† βœ‡ The Register - Security

Seven steps for using zero trust to protect your multicloud estate

June 9th 2023 at 13:22

Your multicloud environment is complex. You need an uncompromising zero trust approach to manage and secure it.

Commissioned Commissioned: If you're like most IT leaders, you are facing two uncomfortable realities. The first is that external and internal cybersecurity threats are proliferating from individuals, independent collectives and nation-state attackers. The second is that your computing operating models are becoming more complex, as their tentacles spread across multicloud environments.…

☐ β˜† βœ‡ The Register - Security

Brit data watchdog fines sleazy sales ops Β£250K for 'bombarding' folk with calls

June 9th 2023 at 11:30

Crown Glazing and Maxen Power Supply fall foul of PECR

Britain's data watchdog has slapped a financial penalty on two energy companies it claims were posing as third parties, including the National Grid and UK government, when making unsolicited marketing calls.…

☐ β˜† βœ‡ The Register - Security

Darkweb credit card marts in decline across Asia, researchers claim

June 9th 2023 at 03:31

India tops the charts for document theft

The number of stolen Asian credit card numbers appearing on darkweb crime marts has fallen sharply, cyber security firm Group-IB told Singapore's ATxSG conference on Thursday.…

☐ β˜† βœ‡ The Register - Security

Google changes email authentication after spoof shows a bad delivery for UPS

June 9th 2023 at 01:02

Google's blue tick proves untrustworthy

Google says it has fixed a flaw that allowed a scammer to impersonate delivery service UPS on Gmail, after the data-hoarding web behemoth labeled the phony email as authentic.…

☐ β˜† βœ‡ The Register - Security

Robot can rip the data out of RAM chips with chilling technology

June 9th 2023 at 00:01

'The more important a thing is for the world, the less security it has' says inventor

Cold boot attacks, in which memory chips can be chilled and data including encryption keys plundered, were demonstrated way back in 2008 – but they just got automated.…

☐ β˜† βœ‡ The Register - Security

North Korea's Lazarus Group linked to Atomic Wallet heist

June 8th 2023 at 23:04

Users' cryptocurrency wallets look unlikely to be refilled

The North Korean criminal gang Lazarus Group has been blamed for last weekend's attack on Atomic Wallet that drained at least $35 million in cryptocurrency from private accounts.…

☐ β˜† βœ‡ The Register - Security

Barracuda tells its ESG owners to 'immediately' junk buggy kit

June 8th 2023 at 21:04

That patch we issued? Yeah, it wasn't enough

Barracuda has now told customers to "immediately" replace infected Email Security Gateway (ESG) appliances β€” even if they have received a patch to fix a critical bug under exploit.…

☐ β˜† βœ‡ The Register - Security

Google puts $1M behind its promise to detect cryptomining malware

June 8th 2023 at 15:00

If the chocolate factory's scans don't stop the miners, customers don't foot the bill

Google Cloud has put $1 million on the table to cover customers' unauthorized compute expenses stemming from cryptomining attacks if its sensors don't spot these illicit miners.…

☐ β˜† βœ‡ The Register - Security

New York City latest to sue Hyundai and Kia claiming their cars are too easy to steal

June 8th 2023 at 14:32

What started as a TikTok craze has become a 'public nuisance'

Hyundai and Kia cars were stolen 977 times in New York City in the first four months of 2023, and authorities have had enough.…

☐ β˜† βœ‡ The Register - Security

On the frontline of cyber threats

June 8th 2023 at 13:00

Watch it here: the unvarnished truth about the state of data security

Webinar Rubrik Zero Lab's annual report on the state of data security is not a comfortable read. And as if to prepare you for what lies inside, the company has called it 'The Hard Truths.'…

☐ β˜† βœ‡ The Register - Security

Microsoft says share the wealth with cyber-info for business

June 8th 2023 at 09:30

It's better to take action than wait for attacks

The timeworn adage that "those who don't learn from history are doomed to repeat it" can certainly be applied to cyber security. Microsoft is hoping to spare enterprises that use its cloud services from repeating history by sharing what it has learned.…

☐ β˜† βœ‡ The Register - Security

Helping Windows 11 fight the hackers

June 8th 2023 at 09:07

How Intel is using hardware-assisted security to beef up Microsoft OS protection

Sponsored Feature When Windows 11 launched in October 2021, one of its big selling points was a new security architecture. Microsoft designed it from the ground up with zero-trust principles in mind, refusing to trust the legitimacy of any single system component. Instead, everything must prove that it has not been compromised.…

☐ β˜† βœ‡ The Register - Security

UK government to set deadline for removal of Chinese surveillance cams

June 8th 2023 at 07:30

And compile a list of vendors considered threats to national security

The UK government will set a deadline for removing made-in-China surveillance cameras from "sensitive sites."…

☐ β˜† βœ‡ The Register - Security

Deepfakes being used in 'sextortion' scams, FBI warns

June 8th 2023 at 00:45

AI technology raises the bar in an already troubling crime

Miscreants are using AI to create faked images of a sexual nature, which they then employ in sextortion schemes.…

☐ β˜† βœ‡ The Register - Security

Clop ransomware crew sets June extortion deadline for MOVEit victims

June 7th 2023 at 19:46

Plus: The Feds weigh in with advice, details

Clop, the ransomware crew that has exploited the MOVEit vulnerability extensively to steal corporate data, has given victims a June 14 deadline to pay up or the purloined information will be leaked.…

☐ β˜† βœ‡ The Register - Security

10 years after Snowden's first leak, what have we learned?

June 7th 2023 at 13:25

Spies gonna spy

Feature The world got a first glimpse into the US government's far-reaching surveillance of American citizens' communications – namely, their Verizon telephone calls – 10 years ago this week when Edward Snowden's initial leaks hit the press.…

☐ β˜† βœ‡ The Register - Security

Police use of PayPal records under fire after raid on 'Cop City' protest fund trio

June 6th 2023 at 23:03

Nearly anything can look like money laundering if you squint hard enough

Three supporters of activists against a $90 million police training facility dubbed Cop City were arrested after the cops used PayPal data to bring money-laundering charges against the trio.…

☐ β˜† βœ‡ The Register - Security

Malwarebytes may not be allowed to label rival's app as 'potentially unwanted'

June 6th 2023 at 19:56

Legal prof warns: 'This case is like a wrecking ball for internet law'

The US Ninth Circuit Court of Appeals last week ruled that Enigma Software Group can pursue its long standing complaint against rival security firm Malwarebytes for classifying its software as "potentially unwanted programs" or PUPs.…

☐ β˜† βœ‡ The Register - Security

US govt now bans TikTok from contractors' work gear

June 6th 2023 at 19:25

BYODALAINGTI (as long as it's not got TikTok installed)

The US federal government's ban on TikTok has been extended to include devices used by its many contractors - even those that are privately owned. The bottom line: if some electronics are used for government work, it better not have any ByteDance bits on it. …

☐ β˜† βœ‡ The Register - Security

Microsoft cops $20M slap on the wrist for mishandling kids' Xbox data

June 6th 2023 at 18:24

Pocket change, in other words

Microsoft is being fined $20 million by the US Federal Trade Commission for violating the Children's Online Privacy Protection Act (COPPA) by illegally gathering kids' personal information and retaining it without parental consent.…

☐ β˜† βœ‡ The Register - Security

Identity thieves can hunt us for 'rest of our lives,' claims suit after university data leak

June 6th 2023 at 17:34

Crooks steal Social Security numbers and post them on dark web, victims blame holes in Mercer's security

An American university founded in 1833 is facing a bunch of class action lawsuits after the personal data of nearly 100,000 people was stolen from its tech infrastructure.…

☐ β˜† βœ‡ The Register - Security

SEC drops 42 cases after staff bungle data protection

June 6th 2023 at 04:02

Corporate watchdog fouled its info-separation regime, let the wrong people read sensitive docs

The US Securities and Exchange Commission (SEC) has dismissed proceedings against 42 companies and individuals after admitting that its enforcement staff accessed documents that were supposed to be for judges' eyes only.…

☐ β˜† βœ‡ The Register - Security

Microsoft stashes nearly half a billion in case LinkedIn data drama hits

June 2nd 2023 at 15:28

Irish regulators sniffing around Facebook-for-suits subsidiary have threatened fine

Microsoft has warned investors about a "non-public" draft decision by Irish regulators against LinkedIn for allegedly dodgy ad data practices, explaining it had set aside some cash to pay off any potential fine.…

☐ β˜† βœ‡ The Register - Security

Taking the art of email security to the next level

June 6th 2023 at 08:28

AI is beefing up the cyber arsenals of both attackers and defenders

Sponsored Feature Email is a popular target for cybercriminals, offering an easy way of launching an attack disguised as an innocent message. One moment of inattention on the part of the recipient and the door is open to malware, spam, phishing, perhaps even a dose of the dreaded ransomware. Entire organisations can suffer, not just individual victims.…

☐ β˜† βœ‡ The Register - Security

British Airways, Boots, BBC payroll data stolen in MOVEit supply-chain attack

June 5th 2023 at 19:29

Microsoft blames Russian Clop ransomware crew for theft of staff info

British Airways, the BBC, and UK pharmacy chain Boots are among the companies whose data has been compromised after miscreants exploited a critical vulnerability in deployments of the MOVEit document-transfer app.…

☐ β˜† βœ‡ The Register - Security

Crypto catastrophe strikes some Atomic Wallet users, over $35M thought stolen

June 5th 2023 at 18:31

Victims nursing huge losses haven't the foggiest how heist happened, yet

As much as $35 million worth of cryptocurrency may have been stolen in a large-scale attack on Atomic Wallet users, with one investigator claiming losses could potentially exceed $50 million.…

☐ β˜† βœ‡ The Register - Security

Qbot malware adapts to live another day … and another …

June 5th 2023 at 12:15

Operators stay ahead of defenders with new access methods and C2 infrastructure

The Qbot malware operation – which started more than a decade ago as banking trojan only to evolve into a backdoor and a delivery system for ransomware and other threats – continues to deftly adapt its techniques to stay ahead of security pros, according to a new report.…

☐ β˜† βœ‡ The Register - Security

Australian cyber-op attacked ISIL with the terrifying power of Rickrolling

June 5th 2023 at 04:29

Commanders in the field persuaded to give up, let their guard down, run around and desert their posts

Australia's Signals Directorate, the signals intelligence organization, has revealed it employed zero-click attacks on devices used by fighters for Islamic State of Iraq and the Levant (ISIL) – then unleashed the terrifying power of Rick Astley.…

☐ β˜† βœ‡ The Register - Security

Toyota admits to yet another cloud leak

June 5th 2023 at 03:30

Also, hackers publish RaidForum user data, Google's $180k Chrome bug bounty, and this week's vulnerabilities

infosec in brief Japanese automaker Toyota is again apologizing for spilling customer records online due to a misconfigured cloud environment – the same explanation it gave when the same thing happened a couple of weeks ago. It's like a pattern.…

☐ β˜† βœ‡ The Register - Security

Meet TeamT5, the Taiwanese infosec outfit taking on Beijing and defeating its smears

June 5th 2023 at 02:33

Living in the eye of the geopolitical storm is not easy, but is good for business

In late September 2021, staff at Taiwanese threat intelligence company TeamT5 noticed something very nasty: a fake news report accusing it of conducting phishing attacks against Japan's government and local tech companies.…

☐ β˜† βœ‡ The Register - Security

Uncle Sam wants DEF CON hackers to pwn this Moonlighter satellite in space

June 3rd 2023 at 08:25

'World's first and only' orbiting infosec playpen due to blast off Sunday

Feature Assuming the weather and engineering gods cooperate, a US government-funded satellite dubbed Moonlighter will launch at 1212 EDT (1612 UTC) on Sunday, hitching a ride on a SpaceX rocket before being releasing into Earth's orbit.…

☐ β˜† βœ‡ The Register - Security

Malaysia goes its own Huawei, won't ban Chinese vendor from 5G network

June 2nd 2023 at 18:33

Country to have two networks as first buildout falls behind schedule

Malaysia could be putting itself on a collision course with the EU and US as the country looks set to allow Chinese suppliers including Huawei a chance to play a part in its planned 5G network rollout.…

☐ β˜† βœ‡ The Register - Security

This malicious PyPI package mixed source and compiled code to dodge detection

June 2nd 2023 at 06:24

Oh cool, something else to scan for

Researchers recently uncovered the following novel attack on the Python Package Index (PyPI).…

☐ β˜† βœ‡ The Register - Security

You might have been phished by the gang that stole North Korea’s lousy rocket tech

June 2nd 2023 at 05:15

US, South Korea, warn 'Kimsuky' is a very sophisticated social engineer

The United States and the Republic of Korea have issued a joint cyber security advisory [PDF] about North Koreas "Kimsuky" cyber crime group.…

❌