FreshRSS

πŸ”’
☐ β˜† βœ‡ The Register - Security

Google bug bounties inch closer to Microsoft's payouts

June 24th 2023 at 14:19

Chocolate Factory paid a record $12m in 2022

Bug hunters who found security holes in Google β€” and also responsibly disclosed details of those flaws to the Chocolate Factory β€” earned more than $12 million in bounty rewards in 2022, marking a record year for the corporation's Vulnerability Reward Programs (VRPs) in terms of payouts and number of vulnerabilities found and fixed.…

☐ β˜† βœ‡ The Register - Security

UK cyberspies warn ransomware crews targeting law firms

June 23rd 2023 at 12:09

Nation states will use you to get to your friends, says NCSC

British law practices of "all sizes and types" have been warned by GCHQ's cyberspy arm that their "widespread adoption of hybrid working" combined with the large sums of money they handle is making them a target.…

☐ β˜† βœ‡ The Register - Security

Keep it schtum!

June 23rd 2023 at 08:53

Ensuring communications stay secure

Webinar The explosion in remote working since the pandemic means the number of people doing their job from home has more than doubled in the UK.…

☐ β˜† βœ‡ The Register - Security

Chinese malware intended to infect USB drives accidentally infects networked storage too

June 23rd 2023 at 05:31

Hides itself from popular Asian AV, also uses games to do its dirty work

Malware intended to spread on USB drives is unintentionally infecting networked storage devices, according to infosec vendor Checkpoint.…

☐ β˜† βœ‡ The Register - Security

US cyber ambassador says China knows how to steal its way to dominance of cloud and AI

June 23rd 2023 at 03:31

Calls on governments to combat 'playbook' that propelled Huawei to prominence

China has a playbook to use IP theft to seize leadership in cloud computing, and other nations should band together to stop that happening, according to Nathaniel C. Fick, the US ambassador-at-large for cyberspace and digital policy.…

☐ β˜† βœ‡ The Register - Security

To kill BlackLotus malware, patching is a good start, but...

June 22nd 2023 at 21:48

...that alone 'could provide a false sense of security,' NSA warns in this handy free guide for orgs

BlackLotus, the malware capable of bypassing Secure Boot protections and compromising Windows computers, has caught the ire of the NSA, which today published a guide to help organizations detect and prevent infections of the UEFI bootkit.…

☐ β˜† βœ‡ The Register - Security

Now BlackCat extortionists threaten to leak stolen plastic surgery pics

June 22nd 2023 at 17:57

Sharing a cancer patient's nude snaps earlier wasn't enough for these scumbags

Ransomware gang BlackCat claims it infected a plastic surgery center, stole "lots" of highly sensitive medical records, and has vowed to leak patients' photos if the clinic doesn't pay up.…

☐ β˜† βœ‡ The Register - Security

The Log4j vulnerability – how can we all do better next time?

June 22nd 2023 at 08:53

Accept there are some risks you don’t control but which nonetheless you can’t ignore

Sponsored Feature Friday the 10 of December 2021 is etched in the memory of many IT professionals, but not for reasons they will look back on with fondness. That was the day, just as most American workers were logging off for a long weekend, when a critical vulnerability in an obscure but essential piece of software code first came to widespread attention.…

☐ β˜† βœ‡ The Register - Security

Japan's digital ID card gets emergency review amid data leaks

June 22nd 2023 at 04:45

PM wants response as urgent as that mustered for COVID-19

Japanese prime minister Fumio Kishida has ordered an emergency review of the nation's ID Cards, amid revelations of glitches and data leaks that threaten the government's digital services push.…

☐ β˜† βœ‡ The Register - Security

A clash of titans

June 22nd 2023 at 03:12

Shielding with protective AI from bad actors using AI for cyberattacks

Webinar The one thing a cyber security team can rarely afford to do is relax its vigilance. But count the collective manhours spent on the frontline and the figure starts to look unsustainable, leaving many organizations with little choice but to engage with technology to help defend against malign intent.…

☐ β˜† βœ‡ The Register - Security

A (cautionary) tale of two patched bugs, both exploited in the wild

June 21st 2023 at 23:14

One affects VMware's monitoring tool and the other TP-Link routers

Miscreants are right now exploiting two security bugs for which patches exist, one in a VMware network and applications monitoring tool and the other in some TP-Link routers.…

☐ β˜† βœ‡ The Register - Security

Apple squashes kernel bug used by TriangleDB spyware

June 21st 2023 at 20:26

Snoops may be targeting macOS in addition to iPhones, Kaspersky says

Whoever is infecting people's iPhones with the TriangleDB spyware may be targeting macOS computers with similar malware, according to Kaspersky researchers.…

☐ β˜† βœ‡ The Register - Security

FTC accuses DNA testing company of lying about dumping samples

June 21st 2023 at 19:30

1Health must strengthen protections for genetic information as part of settlement

The Federal Trade Commission has alleged that genetic testing firm 1Health.io, also known as Vitagene, deceived people when it said it would dispose of their physical DNA sample as well as their collected health data.…

☐ β˜† βœ‡ The Register - Security

Training in Spanish for cyber security pros

June 21st 2023 at 13:25

Sponsored Post Cybercrime is a global phenomenon, but the effectiveness of measures put in place to fight it varies considerably from one region to another.…

☐ β˜† βœ‡ The Register - Security

Oreo cookie maker says crooks gobbled up staff info

June 20th 2023 at 21:01

50K-plus employees' personal info swiped after law firm rolled

Mondelez International has warned 51,000 of its past and present employees that their personal information has been stolen from a law firm hired by the Oreo and Ritz cracker giant.…

☐ β˜† βœ‡ The Register - Security

Reddit confirms BlackCat gang pinched some data

June 20th 2023 at 18:34

Crooks demand $4.5m to keep '80GB' of corp info private – and no API price hikes

Reddit this week confirmed ransomware gang BlackCat, aka AlphaV, broke into its corporate systems in February.…

☐ β˜† βœ‡ The Register - Security

Over 100,000 compromised ChatGPT accounts found for sale on dark web

June 20th 2023 at 10:08

Cybercrooks hoping users have whispered employer secrets to chatbot

UPDATED Singapore-based threat intelligence outfit Group-IB has found ChatGPT credentials in more than 100,000 stealer logs traded on the dark web in the past year.…

☐ β˜† βœ‡ The Register - Security

Data leak at major law firm sets Australia's government and elites scrambling

June 20th 2023 at 05:04

BlackCat attack sparks injunction preventing coverage of purloined docs

An infosec incident at a major Australian law firm has sparked fear among the nation's governments, banks and businesses – and a free speech debate.…

☐ β˜† βœ‡ The Register - Security

Guess what happened to this US agency using outdated software?

June 19th 2023 at 14:32

Also: Hackers target security researchers, MaaS model flourishing, and this week's vulnerabilities

Infosec in brief Remember earlier this year, when we found out that a bunch of baddies including at least one nation-state group broke into a US federal government agency's Microsoft Internet Information Services (IIS) web server by exploiting a critical three-year-old Telerik bug to achieve remote code execution?…

☐ β˜† βœ‡ The Register - Security

Outsource to infill on cyber security

June 19th 2023 at 08:35

Automating, simplifying, and calling in external help can increase the chances of blocking and mitigating attacks

Sponsored Feature Life is tougher than ever for security pros facing a rising tide of cyberattacks. And adversaries are becoming more adept than ever at using diverse methods and technologies to scale up assaults on their selected targets.…

☐ β˜† βœ‡ The Register - Security

With dead-time dump, Microsoft revealed DDoS as cause of recent cloud outages

June 19th 2023 at 00:32

Previous claims its own software updates were the issue remain almost, kinda, plausible

In the murky world of political and corporate spin, announcing bad news on Friday afternoon – a time when few media outlets are watching, and audiences are at a low ebb – is called "taking out the trash." And that’s what Microsoft appears to have done last Friday.…

☐ β˜† βœ‡ The Register - Security

Third MOVEit bug fixed a day after PoC exploit made public

June 16th 2023 at 23:05

Millions of people's personal info swiped, Clop leaks begin with 'Shell's stolen data'

Progress Software on Friday issued a fix for a third critical bug in its MOVEit file transfer suite, a vulnerability that had just been disclosed the day earlier.…

☐ β˜† βœ‡ The Register - Security

LockBit suspect's arrest sheds more light on 'trustworthy' gang

June 16th 2023 at 19:01

Plus: Accused is innocent until proven guilty, but is known to be an Apple fan

FBI agents have arrested a Russian man suspected of being part of the Lockbit ransomware gang. An unsealed complaint alleges the 20-year-old was an Apple fanboy, an online gambler, and scored 80 percent of at least one ransom payment given to the criminals.…

☐ β˜† βœ‡ The Register - Security

Capita faces first legal Letter of Claim over mega breach

June 16th 2023 at 13:04

Barings Law claims 250 people that 'suspect' data theft signed up to class action

Capita is facing its first legal claim over the high profile digital burglary in late March that exposed some customer data to intruders and will cost the outsourcing biz around Β£20 million ($26 million) to clean up.…

☐ β˜† βœ‡ The Register - Security

Microsoft: Russia sent its B team to wipe Ukrainian hard drives

June 16th 2023 at 06:31

WhisperGate-spreading Cadet Blizzard painted as haphazard but dangerous crew

Here's a curious tale about a highly destructive yet flaky Kremlin-backed crew that was active during the early days of Russia's invasion of Ukraine, then went relatively quiet – until this year.…

☐ β˜† βœ‡ The Register - Security

EU boss Breton: There's no Huawei that Chinese comms kit is safe to use in Europe

June 16th 2023 at 00:31

European Commission's own networks to toss Middle Kingdom boxes amid calls for total replacement

European commissioner Thierry Breton wants Huawei and ZTE barred throughout the EU, and revealed plans to remove kit made by the Chinese telecom vendors from the Commission's internal networks.…

☐ β˜† βœ‡ The Register - Security

US government hit by Russia's Clop in MOVEit mass attack

June 15th 2023 at 22:43

CISA chief tells us exploitation 'largely opportunistic', not on same level of SolarWinds

The US Department of Energy and other federal bodies are among a growing list of organizations hit by Russians exploiting the MOVEit file-transfer vulnerability.…

☐ β˜† βœ‡ The Register - Security

Chinese spies blamed for data-harvesting raids on Barracuda email gateways

June 15th 2023 at 18:44

Snoops 'aggressively targeted' specific govt, academic accounts

Chinese spies are behind the data-stealing malware injected into Barracuda's Email Security Gateway (ESG) devices globally as far back as October 2022, according to Mandiant.…

☐ β˜† βœ‡ The Register - Security

North Korea created very phishy evil twin of Naver, South Korea's top portal

June 15th 2023 at 02:15

Think of it as a fake Google tuned for credential capture and you'll understand why authorities want to kill it

North Korea has created a fake version of South Korea's largest internet portal, Naver, in a large scale phishing attempt, Seoul's National Intelligence Service (NIS) said on Wednesday.…

☐ β˜† βœ‡ The Register - Security

Decision to hold women-in-cyber events in abortion-banning states sparks outcry

June 14th 2023 at 23:48

'Many factors were considered,' WiCyS boss tells The Reg as (ISC)Β² suggests an end to 'girlfriend test' jargon

Global nonprofit Women in Cybersecurity (WiCyS), despite months of controversy over the cities named to host its 2024 and 2025 conferences, says it will move forward as planned with the events in Nashville, Tennessee, and Dallas, Texas, respectively.…

☐ β˜† βœ‡ The Register - Security

LockBit victims in the US alone paid over $90m in ransoms since 2020

June 14th 2023 at 19:42

As America, UK, Canada, Australia and friends share essential bible to detect and thwart infections

Seven nations today issued an alert, plus protection tips, about LockBit, the prolific ransomware-as-a-service gang.…

☐ β˜† βœ‡ The Register - Security

Lethal weather

June 14th 2023 at 15:48

Forecasting the flux and flow of threats to the cloud

Webinar The cloud is floating around everywhere and with the rapid expansion of IT always comes new complexities that alter the threat landscape.…

☐ β˜† βœ‡ The Register - Security

Capita wins Β£50M fraud reporting contract with City of London cops

June 14th 2023 at 13:34

No, the irony isn't lost on us either

Capita, which is still dealing with a digital break-in that exposed customers' data to criminals, has scored a Β£50 million contract with the City of London police to run contact and engagement services for the force's fraud reporting service.…

☐ β˜† βœ‡ The Register - Security

Bringing security to account: why identity must be unified

June 14th 2023 at 10:35

As identity management becomes the new security perimeter, cyber risk underwriters want to see resilient IAM control ID sprawl

Sponsored Feature Many organizations are suffering from an identity crisis. Not in the psychological sense, nor in respect to their branding or culture. But in how their IT systems enable employees to access the applications and data they need for work.…

☐ β˜† βœ‡ The Register - Security

Florida man insists he didn't violate the law by keeping Top Secret docs

June 14th 2023 at 00:30

Populist politician pleads not guilty at Miami arraignment

A Florida man and his valet appeared in a Miami federal courtroom on Tuesday to respond to criminal charges of document hoarding and related claims.…

☐ β˜† βœ‡ The Register - Security

June Patch Tuesday: VMware vuln under attack by Chinese spies, Microsoft kinda meh

June 13th 2023 at 20:32

Plus: Adobe, SAP and Android push updates

Microsoft has released security updates for 78 flaws for June's Patch Tuesday, and luckily for admins, none of these are under exploit.…

☐ β˜† βœ‡ The Register - Security

Last of the Gozi 3 sentenced over Windows info-stealing malware ops

June 13th 2023 at 17:33

Banking trojan still going strong as feds put bulletproof hosting point man behind bars

The last of the three men said to be responsible for infecting Windows computers with the banking trojan Gozi has been sentenced to three years.…

☐ β˜† βœ‡ The Register - Security

The commonality of criminal intrusion

June 13th 2023 at 15:07

Rubrik Zero Lab’s β€˜The Hard Truths’ annual report into the state of data security

Webinar It seems no longer possible to imagine whether it's just a case of if a security breach will occur within your organization, or if malicious actors will exploit a vulnerability to play havoc with your data. Rather, it's just a question of when.…

☐ β˜† βœ‡ The Register - Security

These Microsoft Office security signatures are 'practically worthless'

June 13th 2023 at 10:26

Turns out it's easy to forge documents relying on OOXML

Updated Office Open XML (OOXML) Signatures, an Ecma/ISO standard used in Microsoft Office applications and open source OnlyOffice, have several security flaws and can be easily spoofed.…

☐ β˜† βœ‡ The Register - Security

Russia-Ukraine war sending shockwaves into cyber-ecosystem

June 13th 2023 at 08:31

Conflict could be first shooting war to deploy armies of β€˜citizen hackers’ that cause at-risk organisations to rethink their defensive strategies

Sponsored Feature When military historians come to chronicle the first 15 months of the Russian invasion of Ukraine, they won't find any shortage of battlefront bulletins to inform their accounts.…

☐ β˜† βœ‡ The Register - Security

UK telco watchdog Ofcom, Minnesota Dept of Ed named as latest MOVEit victims

June 13th 2023 at 06:28

As another CVE is assigned

Two more organizations hit in the mass exploitation of the MOVEit file-transfer tool have been named – the Minnesota Department of Education in the US, and the UK's telco regulator Ofcom – just days after security researchers discovered additional flaws in Progress Software's buggy suite.…

☐ β˜† βœ‡ The Register - Security

China's cyber now aimed at infrastructure, warns CISA boss

June 13th 2023 at 04:45

Resilience against threats needs a boost

China's cyber-ops against the US have shifted from espionage activities to targeting infrastructure and societal disruption, the director of the Cybersecurity and Infrastructure Security Agency (CISA) Jen Easterly told an Aspen Institute event on Monday.…

☐ β˜† βœ‡ The Register - Security

India probes medical info 'leak' to Telegram

June 13th 2023 at 03:26

PLUS: Vietnam's free domain names for youngsters; China's Cuba spy base; Hyundai and Samsung team for car chips; and more

Asia In Brief India's government has denied its Co-WIN COVID-19 vaccination management platform has leaked data, but ordered an investigation into the program's security.…

☐ β˜† βœ‡ The Register - Security

Unsealed: Charges against Russians blamed for Mt Gox crypto-exchange collapse

June 12th 2023 at 23:23

What a blast from the past, the past being a year before the pandemic

American prosecutors have unsealed an indictment against two Russians who allegedly had a hand in the ransacking and collapse of Mt Gox a decade ago, an implosion that cost the cryptocurrency exchange's thousands of customers most of their digital coins.…

☐ β˜† βœ‡ The Register - Security

Fortinet squashes hijack-my-VPN bug in FortiOS gear

June 12th 2023 at 21:06

And it's already being exploited in the wild, probably

Fortinet has patched a critical bug in its FortiOS and FortiProxy SSL-VPN that can be exploited to hijack the equipment.…

☐ β˜† βœ‡ The Register - Security

Posing as journalists, Pink Drainer pilfers $3.3M in crypto

June 12th 2023 at 20:00

First the interview, then the phishing attack

Miscreants targeting Discord and Twitter accounts have stolen more than $3.3 million in cryptocurrency from 2,300 victims so far in an ongoing campaign that started in April and saw the highest spike in activity earlier this month.…

☐ β˜† βœ‡ The Register - Security

Microsoft stole our stolen dark web data, says security outfit

June 12th 2023 at 19:15

Suit claims Redmond took far more than allowed from Hold's 360M-credential database

Microsoft stands accused by cyber intelligence firm Hold Security of violating an agreement between the pair by misusing Hold's database of more than 360 million sets of credentials culled from the dark web.…

☐ β˜† βœ‡ The Register - Security

Lantum S3 bucket leak is prescription for chaos for thousands of UK doctors

June 12th 2023 at 12:34

Freelance agency exposed personal details that would be highly valuable in the wrong hands

Updated A UK agency for freelance doctors has potentially exposed personal details relating to 3,200 individuals via unsecured S3 buckets, which one expert said could be used to launch ID theft attacks or blackmail.…

☐ β˜† βœ‡ The Register - Security

Hold it – another vulnerability found in MOVEit file transfer software

June 12th 2023 at 10:33

Also, the FBI's $180k investment in AN0M keeps paying off, and this week's critical vulnerabilities

Infosec in brief Security firms helping Progress Software dissect the fallout from a ransomware attack against its MOVEit file transfer suite have discovered an additional exploitable bug.…

☐ β˜† βœ‡ The Register - Security

Online muggers make serious moves on unpatched Microsoft bugs

June 9th 2023 at 23:47

Win32k and Visual Studio flaws are under attack

Two flaws in Microsoft software are under attack on systems that haven't been patched by admins.…

☐ β˜† βœ‡ The Register - Security

FBI: FISA Section 702 'absolutely critical' to spy on, err, protect Americans

June 9th 2023 at 20:30

No protection without surveillance?

The FBI doesn't want to lose its favorite codified way to spy, Section 702 of the US Foreign Intelligence Surveillance Act. In its latest salvo, the agency's deputy director Paul Abbate called it "absolutely critical for the FBI to continue protecting the American people."…

☐ β˜† βœ‡ The Register - Security

Ransomware scum hit Japanese pharma giant Eisai Group

June 9th 2023 at 17:30

Some servers encrypted in weekend attack, but product supply not affected

Japanese pharma giant Eisai today confirmed to The Register that "there is no imminent risk of stock shortage" after it was hit by ransomware at the weekend.…

☐ β˜† βœ‡ The Register - Security

Seven steps for using zero trust to protect your multicloud estate

June 9th 2023 at 13:22

Your multicloud environment is complex. You need an uncompromising zero trust approach to manage and secure it.

Commissioned Commissioned: If you're like most IT leaders, you are facing two uncomfortable realities. The first is that external and internal cybersecurity threats are proliferating from individuals, independent collectives and nation-state attackers. The second is that your computing operating models are becoming more complex, as their tentacles spread across multicloud environments.…

☐ β˜† βœ‡ The Register - Security

Brit data watchdog fines sleazy sales ops Β£250K for 'bombarding' folk with calls

June 9th 2023 at 11:30

Crown Glazing and Maxen Power Supply fall foul of PECR

Britain's data watchdog has slapped a financial penalty on two energy companies it claims were posing as third parties, including the National Grid and UK government, when making unsolicited marketing calls.…

☐ β˜† βœ‡ The Register - Security

Darkweb credit card marts in decline across Asia, researchers claim

June 9th 2023 at 03:31

India tops the charts for document theft

The number of stolen Asian credit card numbers appearing on darkweb crime marts has fallen sharply, cyber security firm Group-IB told Singapore's ATxSG conference on Thursday.…

☐ β˜† βœ‡ The Register - Security

Google changes email authentication after spoof shows a bad delivery for UPS

June 9th 2023 at 01:02

Google's blue tick proves untrustworthy

Google says it has fixed a flaw that allowed a scammer to impersonate delivery service UPS on Gmail, after the data-hoarding web behemoth labeled the phony email as authentic.…

☐ β˜† βœ‡ The Register - Security

Robot can rip the data out of RAM chips with chilling technology

June 9th 2023 at 00:01

'The more important a thing is for the world, the less security it has' says inventor

Cold boot attacks, in which memory chips can be chilled and data including encryption keys plundered, were demonstrated way back in 2008 – but they just got automated.…

☐ β˜† βœ‡ The Register - Security

North Korea's Lazarus Group linked to Atomic Wallet heist

June 8th 2023 at 23:04

Users' cryptocurrency wallets look unlikely to be refilled

The North Korean criminal gang Lazarus Group has been blamed for last weekend's attack on Atomic Wallet that drained at least $35 million in cryptocurrency from private accounts.…

☐ β˜† βœ‡ The Register - Security

Barracuda tells its ESG owners to 'immediately' junk buggy kit

June 8th 2023 at 21:04

That patch we issued? Yeah, it wasn't enough

Barracuda has now told customers to "immediately" replace infected Email Security Gateway (ESG) appliances β€” even if they have received a patch to fix a critical bug under exploit.…

☐ β˜† βœ‡ The Register - Security

Google puts $1M behind its promise to detect cryptomining malware

June 8th 2023 at 15:00

If the chocolate factory's scans don't stop the miners, customers don't foot the bill

Google Cloud has put $1 million on the table to cover customers' unauthorized compute expenses stemming from cryptomining attacks if its sensors don't spot these illicit miners.…

❌