FreshRSS

πŸ”’
☐ β˜† βœ‡ The Register - Security

Mattress maker Tempur Sealy says it isolated tech system to contain cyber burglary

August 1st 2023 at 14:31

Sleeping giant says no sign yet personal info was stolen

Tempur Sealy, among the world's largest providers of bedding, has notified the Securities and Exchange Commission of a digital burglary by cyber crims that forced it to isolate parts of the tech infrastructure.…

☐ β˜† βœ‡ The Register - Security

US military battling cyber threats from within and without

August 1st 2023 at 07:29

As if attacks from China weren't enough, one of the Air Force's own has reportedly gone rogue

The US government is fighting a pair of cyber security incidents, one involving Chinese spies who potentially gained access to crucial American computer networks and the other related to an Air Force engineer allegedly compromised communications security by stealing sensitive equipment and taking it home.…

☐ β˜† βœ‡ The Register - Security

China bans export of drones some countries have already banned anyway

August 1st 2023 at 06:00

Some say retaliation for sanctions, but Beijing says it just wants world peace

China introduced restrictions on Monday that mean would-be exporters will require a license to ship certain drones and related equipment out of the Middle Kingdom.…

☐ β˜† βœ‡ The Register - Security

White House: Losing Section 702 spy powers would be among 'worst intelligence failures of our time'

July 31st 2023 at 19:58

As expert panel suggests some tweaks to boost public's confidence in FISA

The White House has weighed in on the Section 702 debate, urging lawmakers to reauthorize, "without new and operationally damaging restrictions," the controversial snooping powers before they expire at the end of the year.…

☐ β˜† βœ‡ The Register - Security

Hikvision, Nvidia named in contract for 'Uyghur detection'

July 31st 2023 at 12:25

GPU giant says you can't stop secondary sales, surveillance gear maker maintains innocence

Updated Video surveillance equipment maker Hikvision was paid $6 million by the Chinese government last year to provide technology that could identify members of the nation's Uyghur people, a Muslim ethnic majority, according to physical security monitoring org IPVM.…

☐ β˜† βœ‡ The Register - Security

What would sustainable security even look like?

July 31st 2023 at 08:30

Clue: Nothing like what’s on offer today

Opinion "There seems to be something wrong with our bloody ships today," fumed Admiral David Beatty during 1916's Battle of Jutland. Fair enough: three of the Royal Navy's finest vessels had just blown up and sank.…

☐ β˜† βœ‡ The Register - Security

US senator victim-blames Microsoft for Chinese hack

July 31st 2023 at 00:59

ALSO: China says US hacked it right back, BreachForums users have been pwned, and this week's critical vulns

Infosec in brief US senator Ron Wyden (D-OR) thinks it's Microsoft's fault that Chinese hackers broke into Exchange Online, and he wants three separate government agencies to launch investigations and hold the Windows giant "responsible for its negligent cyber security practices." …

☐ β˜† βœ‡ The Register - Security

Florida man accused of hoarding America's secrets faces fresh charges

July 29th 2023 at 00:59

Mar-a-Lago IT director told 'the boss wanted the server deleted'

Federal prosecutors have expanded their criminal case against a famous Floridian and his loyal minions for allegedly mishandling national security secrets and not being forthright about the storage and handling of hundreds of classified documents.…

☐ β˜† βœ‡ The Register - Security

Millions of people's data stolen because web devs forget to check access perms

July 29th 2023 at 00:09

IDORs of the storm

Personal, financial, and health information belonging to millions of folks has been stolen via a particular class of website vulnerability, say cybersecurity agencies in the US and Australia. They're urging developers to review their code and squish these bugs for good.…

☐ β˜† βœ‡ The Register - Security

FBI boss: Congress must renew Section 702 spy powers – that's how we get nearly all our cyber intel

July 28th 2023 at 19:52

Also: China's 'got a bigger hacking program than that of every major nation combined'

Nearly all of the FBI's technical intelligence on malicious "cyber actors" in the first half of this year was obtained via Section 702 searches, according to FBI Director Christopher Wray.…

☐ β˜† βœ‡ The Register - Security

Chinese companies evade sanctions, fuel Moscow’s war on Ukraine, says report

July 28th 2023 at 19:27

PRC semiconductor exports curiously rose 19% y-o-y for first 9 months of 2022

Chinese companies, including state-owned defense companies, are evading tech sanctions and fueling Moscow’s war in Ukraine, according to a US report released on Thursday.…

☐ β˜† βœ‡ The Register - Security

NATO probes hacktivist crew's boasts of stolen portal data

July 27th 2023 at 22:33

'Gay furry hackers' say it's in response to 'attacks on human rights' and noooothing to do with Russia-Ukraine

NATO is investigating claims by miscreants that they broke into the military alliance's unclassified information-sharing and collaboration IT environment, stole information belonging to 31 nations, and leaked 845 MB of compressed data.…

☐ β˜† βœ‡ The Register - Security

Medical files of 8M-plus people fall into hands of Clop via MOVEit mega-bug

July 27th 2023 at 20:01

Maximus plus Deloitte and Chuck E. Cheese join 500+ victim orgs

Accounting giant Deloitte, pizza and birthday party chain Chuck E. Cheese, government contractor Maximus, and the Hallmark Channel are among the latest victims that the Russian ransomware crew Clop claims to have compromised via the MOVEit vulnerability.…

☐ β˜† βœ‡ The Register - Security

Think tank calls for monitoring of Chinese AI-enabled products

July 27th 2023 at 18:54

Will make regulating China’s 5G telecom equipment look like a cinch

Chinese made AI-enabled products should spark similar concerns to Middle Kingdom sourced 5G equipment and therefore be regulated, said think tank Australian Strategic Policy Institute (ASPI) on Thursday.…

☐ β˜† βœ‡ The Register - Security

Crooks pwned your servers? You've got four days to tell us, SEC tells public companies

July 26th 2023 at 23:48

Cripes, they actually sound serious

Public companies that suffer a computer crime likely to cause a "material" hit to an investor will soon face a four-day time limit to disclose the incident, according to rules approved today by the US Securities and Exchange Commission.…

☐ β˜† βœ‡ The Register - Security

Russia throws founder of infosec biz Group-IB in the clink for treason

July 26th 2023 at 20:31

Sachkov faces 14-year stretch after 'unreasonably rushed trial'

A Russian court has sentenced Ilya Sachkov, the founder of security research house Group-IB, to 14 years in a maximum-security prison after finding the executive guilty of high treason.…

☐ β˜† βœ‡ The Register - Security

Ambulance patient records system hauled offline for cyber-attack probe

July 26th 2023 at 09:01

UK trusts serving 12 million people affected as vendor awaits results of forensic investigation

Several UK NHS ambulance organizations have been struggling to record patient data and pass it to other providers following a cyber-attack aimed at health software company Ortivus.…

☐ β˜† βœ‡ The Register - Security

Sneaky Python package security fixes help no one – except miscreants

July 26th 2023 at 07:28

Good thing these eggheads have created a database of patches

Python security fixes often happen through "silent" code commits, without an associated Common Vulnerabilities and Exposures (CVE) identifier, according to a group of computer security researchers.…

☐ β˜† βœ‡ The Register - Security

Ivanti plugs critical bug – but not before it was used against Norwegian government

July 26th 2023 at 06:27

Uncle Sam warns sysadmins to get patching as soon as possible

A critical security flaw in Ivanti's mobile endpoint management code was exploited and used to compromise 12 Norwegian government agenciesΒ before the vendor plugged the hole.…

☐ β˜† βœ‡ The Register - Security

Apple patches exploited bugs in iPhones plus other holes

July 25th 2023 at 21:29

One spotted by Amnesty International - wonder what that was used for?

Apple has released fixes for several security flaws that affect its iPhones, iPads, macOS computers, and Apple TV and watches, and warned that some of these bugs have already been exploited.…

☐ β˜† βœ‡ The Register - Security

TETRA radio comms used by emergency heroes easily cracked, say experts

July 24th 2023 at 23:20

If it looks like a backdoor, walks like a backdoor, maybe it's ... export control

Updated Midnight Blue, a security firm based in the Netherlands, has found five vulnerabilities that affect Terrestrial Trunked Radio (TETRA), used in Europe, the United Kingdom, and many other countries by government agencies, law enforcement, and emergency services organizations.…

☐ β˜† βœ‡ The Register - Security

AMD Zenbleed chip bug leaks secrets fast and easy

July 24th 2023 at 20:41

Zen 2 flaw more simple than Spectre, exploit code already out there – get patching when you can

AMD has started issuing some patches for its processors affected by a serious silicon-level bug dubbed Zenbleed that can be exploited by rogue users and malware to steal passwords, cryptographic keys, and other secrets from software running on a vulnerable system.…

☐ β˜† βœ‡ The Register - Security

Google Cloud shores up log permissions for builder bot

July 24th 2023 at 04:08

ALSO: Amazon's child-sized COPPA fine, smart tech security labels coming to the US, and this week's critical vulns

Infosec in brief Google Cloud has fixed an issue in which it gave away a little too much info in its audit logs to a service account.…

☐ β˜† βœ‡ The Register - Security

Stolen Microsoft key may have opened up a lot more than US govt email inboxes

July 21st 2023 at 22:58

How does the Azure giant come back from this?

A stolen Microsoft security key may have allowed Beijing-backed spies to break into a lot more than just Outlook and Exchange Online email accounts.…

☐ β˜† βœ‡ The Register - Security

VirusTotal: We're sorry someone fat-fingered and exposed 5,600 users

July 21st 2023 at 20:58

File under PEBCAK

VirusTotal today issued a mea culpa, saying a blunder earlier this week by one of its staff exposed information belonging to 5,600 customers, including the email addresses of US Cyber Command, FBI, and NSA employees.…

☐ β˜† βœ‡ The Register - Security

Lawyer sees almost 1,000 complainants sign up to Capita breach class action

July 21st 2023 at 10:38

95% pertain to pension schemes administered by outsourcing giant, says Barings Law

The law firm that last month sent a Letter of Claim to Capita over a security breach in late March says it has signed up nearly 1,000 clients as it prepares a class action lawsuit aimed at the outsourcing giant.…

☐ β˜† βœ‡ The Register - Security

MOVEit body count closes in on 400 orgs, 20M+ individuals

July 20th 2023 at 21:01

'One of the most significant hacks of recent years,' we're told

The number of victims and costs tied to the MOVEit file transfer hack continues to climb as the fallout from the massive supply chain attack enters week seven.…

☐ β˜† βœ‡ The Register - Security

RIP Kevin Mitnick: Former most-wanted hacker dies at 59

July 20th 2023 at 18:01

Tributes paid to husband, father, son and rogue-turned-consultant

Obit Kevin Mitnick, probably the world's most-famous computer hacker – and subsequently writer, public speaker, and security consultant – has succumbed to pancreatic cancer. He was 59.…

☐ β˜† βœ‡ The Register - Security

Under CISA pressure collab, Microsoft makes cloud security logs available for free

July 20th 2023 at 12:30

In hindsight, it's probably good practice to give clients access to cloud logs

Microsoft announced on Wednesday it would provide all customers free access to cloud security logs – a service usually reserved for premium clients – within weeks of a reveal that government officials' cloud-based emails were targets of an alleged China-based hack.…

☐ β˜† βœ‡ The Register - Security

Ukraine busts bot farm spreading Russian infowar propaganda and fraud

July 20th 2023 at 07:30

Plus: Spanish cops arrest Ukrainian scareware dev after ten-year hunt

Ukrainian cops have disrupted a massive bot farm with more than 100 operators allegedly spreading fake news about the Russian invasion, leaking personal information belonging to Ukrainian citizens, and instigating fraud schemes.…

☐ β˜† βœ‡ The Register - Security

Tech support scammers go analog, ask victims to mail bundles of cash

July 19th 2023 at 21:00

The approach is the same, but never mind the crypto or gift cards

Cybercriminals are taking their business offline in a new approach to familiar technical support scams recently identified by the US Federal Bureau of Investigation.…

☐ β˜† βœ‡ The Register - Security

INTERSECT '23: Network Security Summit unveils cutting-edge strategies to safeguard digital assets

July 19th 2023 at 09:45

Palo Alto Networks addresses the mounting challenges posed by sophisticated cyberthreats

Sponsored Post Join Palo Alto Networks at the INTERSECT '23: Network Security Summit, on July 27, 2023 09:00 AM PDT in the Americas and on August 2, 2023, at 10:00 AM CEST in Europe.…

☐ β˜† βœ‡ The Register - Security

US adds Euro spyware makers to export naughty list

July 18th 2023 at 23:42

Predator dev joins Pegasus slinger

The US government on Tuesday added commercial spyware makers Intellexa and Cytrox to its Entity List, saying the duo are a possible threat to national security.…

☐ β˜† βœ‡ The Register - Security

Recycling giant TOMRA pulls systems offline following 'extensive cyberattack'

July 18th 2023 at 12:59

Says baddies launched attack at weekend, isolates parts of tech infrastructure to contain spread

Norwegian mining and recycling giant TOMRA says it has isolated tech systems as it deals with an "extensive cyberattack."…

☐ β˜† βœ‡ The Register - Security

Cybercrime – big in Asia Pacific

July 18th 2023 at 02:43

SANS first DFIR Summit in Asia gives organizations in Asia Pacific an opportunity to build their cyber security expertise

Sponsored Post Kroll's latest State of Incident Response: APAC report suggests that over half of all organizations in Asia Pacific (59 percent) have experienced a cyber incident, of which a third (32 percent) have suffered multiple incidents.…

☐ β˜† βœ‡ The Register - Security

Quick: Manually patch this Zimbra bug that's under attack

July 17th 2023 at 21:49

Smells like Russian cyber spies (again)

A vulnerability in Zimbra's software is being exploited right now by miscreants to compromise systems and attack selected government organizations, experts reckon.…

☐ β˜† βœ‡ The Register - Security

Beijing wants to make the Great Firewall of China even greater

July 17th 2023 at 18:28

Also more fiery, with vague but firm orders to create a 'security barrier'

Over the weekend Chinese president Xi Jinping gave a directive to officials to build a Beijing-supervised "security barrier" around its internet.…

☐ β˜† βœ‡ The Register - Security

Boris Johnson pleads ignorance, which just might work

July 17th 2023 at 02:20

Also: More high-profile MOVEit victims; CVSS 4.0 coming soon; and a long list of critical vulnerabilities

Infosec in brief Former UK prime minister Boris Johnson lobbed a wrench into the works of the country's COVID-19 inquiry by claiming he couldn't remember the passcode to unlock an old phone being sought by investigators.…

☐ β˜† βœ‡ The Register - Security

Infosec watchers: TeamTNT crew may blast holes in Azure, Google Cloud users

July 15th 2023 at 08:28

Why limit yourself to only stealing AWS credentials?

A criminal crew with a history of deploying malware to harvest credentials from Amazon Web Services accounts may expand its attention to organizations using Microsoft Azure and Google Cloud Platform.…

☐ β˜† βœ‡ The Register - Security

Celsius feels the heat: Ex-CEO arrested, watchdogs line up to sue bankrupt crypto biz

July 13th 2023 at 20:48

Exec faces fraud charges, one regulator wants $5 billion fine

Alex Mashinsky, the now-former CEO of collapsed cryptocurrency concern Celsius, today faces charges of fraud as prosecutors and watchdogs pile in.…

☐ β˜† βœ‡ The Register - Security

Microsoft whips up unrest after revealing Azure AD name change

July 12th 2023 at 17:02

Ditching it after a decade? Devs warn of the hours to correct documentation and chaos it'll cause

Microsoft is causing a stir among some tech pros after confirming it plans to rename Azure AD to Entra.…

☐ β˜† βœ‡ The Register - Security

Miscreants exploit five Microsoft bugs as Windows giant addresses 130 flaws

July 11th 2023 at 23:26

Plus: Apple bungles another rapid security response; important ICS updates land; and more

Patch Tuesday Microsoft today addressed 130 CVE-listed vulnerabilities in its products – and five of those bugs have already been exploited in the wild.…

☐ β˜† βœ‡ The Register - Security

Barts NHS hack leaves folks on tenterhooks over extortion

July 11th 2023 at 07:32

BlackCat pounces on 7TB of data and theatens to release it

Staff at one of the UK's largest hospital groups have spent a nervous week wondering if private data, stolen from their employer's IT systems by a ransomware gang, is going to be splurged online after a deadline to prevent publication passed.…

☐ β˜† βœ‡ The Register - Security

LibertΓ©, Γ‰galitΓ©, Spyware: France okays cops snooping on phones

July 10th 2023 at 05:33

ALSO: Shell fails to learn from past leaks; hundreds of solar plants found open to Mirai; and this week's crit vulns

Infosec in brief With riots rocking the country, French parliamentarians have passed a bill granting law enforcement the right to snoop on suspects via "the remote activation of an electronic device without the knowledge or consent of its owner." …

☐ β˜† βœ‡ The Register - Security

Capita staffers told attackers stole data from its own pension fund

July 7th 2023 at 12:11

Three months after mega breach by Russian cybercrime group

Capita has informed some of its employees that its own pension fund was among the victims of a cybercrime attack on its system, resulting in the theft of their personal details, they say.…

☐ β˜† βœ‡ The Register - Security

Nickelodeon probes claims of massive data leak as SpongeBob fans rejoice

July 6th 2023 at 22:45

TV network's attorneys 'on a DMCA rampage' ... are you sure you're ready, kids?

Nickelodeon says it is probing claims that "decades old" material was stolen from it and leaked online. This follows reports on social media that someone had dumped 500GB of snatched animation files. Hilarity, and many SpongeBob SquarePants memes, ensued.…

☐ β˜† βœ‡ The Register - Security

Microsoft puts out Outlook fire, says everything's fine with Teams malware flaw

July 6th 2023 at 21:20

Redmond's not fixing the latter because it 'relies on social engineering'

Microsoft is having a rough week with troubles including an Outlook.com bug that prevented some email users from searching their messages for several hours on Thursday, and a Teams flaw that allows people to send phishing emails and malware to other Teams users.…

☐ β˜† βœ‡ The Register - Security

LockBit louts unload ransomware at Japan’s most prolific cargo port

July 6th 2023 at 03:13

Nagoya Harbor hit the rocks yesterday but looks to be afloat once more

The port of Nagoya – which shifted 2.68 million shipping containers and 164 million tons of cargo in 2022 – has moved precious few in the last 24 hours after finding itself the latest victim of Russia's notorious LockBit ransomware gang.…

☐ β˜† βœ‡ The Register - Security

North Korean satellite had no military utility for spying, says South Korea

July 6th 2023 at 00:30

Lends credence to theory that Pyongyang is testing ballistic missiles against international rules

A North Korean satellite allegedly designed for reconnaissance was not viable for its alleged intended purpose, according to South Korea's military on Wednesday.…

☐ β˜† βœ‡ The Register - Security

Ex-Amazon manager jailed for stealing $10M using fake vendor invoices

July 6th 2023 at 00:28

Prime doesn't pay – well, not that much, anyway

A now-former Amazon manager described by prosecutors as the "mastermind" behind a nearly $10 million scheme to steal money from the online megaretailer using fake invoices has been sentenced to 16 years behind bars in federal prison.…

☐ β˜† βœ‡ The Register - Security

RAM-ramming Rowhammer is back – to uniquely fingerprint devices

July 5th 2023 at 21:14

Just use it sparingly, as it may crash equipment or burn out memory

Boffins at the University of California, Davis have devised a purportedly practical way to apply a memory abuse technique called Rowhammer to build unique, stable device fingerprints.…

☐ β˜† βœ‡ The Register - Security

Suspected bank-infecting OPERA1ER crime boss cuffed

July 5th 2023 at 19:40

Cops reckon gang swiped as much as $30M from financial orgs

International cops have arrested a suspected "key figure" of a cybercrime group dubbed OPERA1ER that has stolen as much as $30 million from more than 30 banks and financial orgs across 15 countries.…

☐ β˜† βœ‡ The Register - Security

Singapore tells crypto operators: act like grown up financial institutions

July 5th 2023 at 06:24

Digital payment skeptics of the world, unite! You have nothing to lose but grifters and crims

Singapore has joined the ranks of nations requiring digital payment operators to follow the same sort of regulations and customer protection requirements that apply to conventional financial institutions.…

☐ β˜† βœ‡ The Register - Security

Undiplomatic Chinese threat actor attacks embassies and foreign affairs departments

July 4th 2023 at 05:29

Sneaky HTML smuggling signals MustangPanda shift towards Europe, Checkpoint charges

Infosec outfit Checkpoint says it's spotted a Chinese actor targeting diplomatic facilities around Europe.…

☐ β˜† βœ‡ The Register - Security

You've patched right? '340K+ Fortinet firewalls' wide open to critical security bug

July 3rd 2023 at 23:17

That's a vulnerability that's under attack, fix available ... cancel those July 4th plans, perhaps?

More than 338,000 FortiGate firewalls are still unpatched and vulnerable to CVE-2023-27997, a critical bug Fortinet fixed last month that's being exploited in the wild.…

☐ β˜† βœ‡ The Register - Security

TSA wants to expand facial recognition to hundreds of airports within next decade

July 3rd 2023 at 22:12

Digital rights folks, as you can imagine, want the tech grounded

America's Transportation Security Agency (TSA) intends to expand its facial-recognition program used to screen US air travel passengers to 430 domestic airports in under a decade.…

☐ β˜† βœ‡ The Register - Security

Dublin Airport staff pay data 'compromised' by criminals

July 3rd 2023 at 15:14

Attackers accessed it via third-party services provider, says management group

It's an awkward Monday for Dublin Airport after pay and benefits details for some 2,000 staff were apparently "compromised" following a recent attack on professional service provider Aon.…

☐ β˜† βœ‡ The Register - Security

US authorities warn on China's new counter-espionage law

July 3rd 2023 at 06:28

Almost anything you download from China could be considered spying, but at least one analyst isn't worried

The United States' National Counterintelligence and Security Center (NCSC) has warned that China's updated Counter-Espionage law – which came into effect on July 1 – is dangerously ambiguous and could pose a risk to global business.…

☐ β˜† βœ‡ The Register - Security

Japan rebukes Fujitsu for cloud security fails

July 3rd 2023 at 01:35

PLUS: Philippines cyber-slave raid; South Korea’s crypto crackdown; AWS boosts Chinese exports; and more

Asia In Brief Japan's government last Friday rebuked Fujitsu for shabby cloud security.…

☐ β˜† βœ‡ The Register - Security

Us, hacked by LockBit? No, says TSMC, that would be our IT supplier

June 30th 2023 at 23:17

So, uh, who's gonna pay that $70M ransom?

Following claims by ransomware gang LockBit that it has stolen data belonging to TSMC, the chip-making giant has said it was in fact one of its equipment suppliers, Kinmax, that was compromised by the crew, and not TSMC itself.…

❌