FreshRSS

πŸ”’
☐ β˜† βœ‡ The Register - Security

SEC fines fintech crypto fund that promised 2,700% returns

August 22nd 2023 at 15:34

Titan Global Capital Management to pay $1m to those it advised without admitting fault

A New York fintech biz is set to pay $1 million in fines under a US Securities and Exchange Commission order that claims it advertised "annualized" returns on Titan Crypto of up to 2,700 percent, a number based on a "purely hypothetical account."…

☐ β˜† βœ‡ The Register - Security

The devil in the detail

August 22nd 2023 at 12:46

How AI is powering ransomware attacks on applications

Webinar You could be forgiven for wondering if anything can ever again be completely straightforward or demonstrably authentic in a world where generative AI can masquerade convincingly as your mother, or express itself in the exact language your best friend might use.…

☐ β˜† βœ‡ The Register - Security

Apple's defense against apps vandalizing other apps still broken, developer claims

August 22nd 2023 at 08:27

Cupertino appears to be blasΓ© about long-standing macOS bug, so coder has blabbed

Updated Apple last year introduced a security feature called App Management that's designed to prevent one application from modifying another without authorization under macOS Ventura – but a developer claims it’s not very good at its job under some circumstances.…

☐ β˜† βœ‡ The Register - Security

Ivanti Sentry exploited in the wild, patches emitted

August 22nd 2023 at 00:30

Good thing you're not exposing admin port 8443 to the world, right? Uh, right?

A critical authentication bypass bug in MobileIron Sentry has been exploited in the wild, its maker Ivanti said in an advisory on Monday.…

☐ β˜† βœ‡ The Register - Security

Uncle Sam: Rest of the world would love to steal our space blueprints – don't let 'em

August 21st 2023 at 21:54

If spies aren't swiping designs via joint ventures, they're breaking into IT networks and mulling sat hijackings

With America outspending the rest of the world on space technologies, those systems and their blueprints are a highly alluring and lucrative target for sticky-fingered spies, Uncle Sam has reminded industry.…

☐ β˜† βœ‡ The Register - Security

Leak of 75k employee records was insiders' fault, claims Tesla

August 21st 2023 at 17:35

Identity Access Management? What's that?

Insiders are to blame for a May data breach at Tesla, the company claimed in filings after news of the incident was reported months ago by German media.…

☐ β˜† βœ‡ The Register - Security

High severity vuln in WinRAR could allow code to run when files are opened

August 21st 2023 at 13:35

Update now: Millions of users potentially impacted, plus uncounted warez folks

Users of the popular WinRAR compression and archiving tool should update now to avoid a vulnerability that allows code to be run when a user opens a RAR file.…

☐ β˜† βœ‡ The Register - Security

Last rites for the UK's Online Safety Bill, an idea too stupid to notice it's dead

August 21st 2023 at 08:31

Snoopers Charter: Dead cows don't snitch

Opinion Information wants to be free. This usefully ambiguous battle cry has been the mischievous slogan of hackers since early networking thinker Stuart Brand coined it in the early 1980s. Intended as part of a discussion about the inherent contradictions of intellectual property, it has bestowed irony in many other places since.…

☐ β˜† βœ‡ The Register - Security

Microsoft DNS boo-boo breaks Hotmail for users around the globe

August 21st 2023 at 03:34

ALSO: NYC says kthxbye to TikTok, slain Microsoft exec's wife indicted, and some ASAP patch warnings

Infosec in brief Someone at Microsoft has some explaining to do after a messed-up DNS record caused emails sent from accounts using Microsoft's Outlook Hotmail service to be rejected and directed to spam folders starting on Thursday.…

☐ β˜† βœ‡ The Register - Security

Interpol arrests 14 who allegedly scammed $40m from victims in 'cyber surge'

August 20th 2023 at 07:18

Cops credit security shops with an assist, tho it's a drop in the ocean

An Interpol-led operation arrested 14 suspects and identified 20,674 "suspicious" networks spanning 25 African countries that international cops have linked to more than $40 million in cybercrime losses.…

☐ β˜† βœ‡ The Register - Security

FYI: There's another BlackCat ransomware variant on the prowl

August 18th 2023 at 21:33

Bad kitty, no catnip for you

Here's a heads up. Another version of BlackCat ransomware has been spotted extorting victims. This variant embeds two tools, we're told: the network toolkit Impacket for lateral movement within compromised environments, and Remcom for remote code execution.…

☐ β˜† βœ‡ The Register - Security

Add 'writing malware' to the list of things generative AI is not very good at doing

August 18th 2023 at 00:39

But it may help with fuzzing

Analysis Despite the hype around criminals using ChatGPT and various other large language models to ease the chore of writing malware, it seems this generative AI technology isn't terribly good at helping with that kind of work.…

☐ β˜† βœ‡ The Register - Security

Don't just patch your Citrix gear, check for intrusion: Two bugs exploited in wild

August 17th 2023 at 21:55

About 2,000 NetScaler installations feared compromised as CISA raises alarm over ShareFile

Updated Miscreants are actively exploiting critical bugs in two of Citrix's products, both of which the business IT player fixed earlier this summer.…

☐ β˜† βœ‡ The Register - Security

Man arrested in Northern Ireland police data leak as more incidents come to light

August 17th 2023 at 12:03

Plus laptop and radio with yet more officers details reportedly nicked from car

A man was arrested in Northern Ireland for suspected Collection of Terrorist Information following an incident where police mistakenly leaked details that identified 10,000 serving officers, but he has now been released on bail.…

☐ β˜† βœ‡ The Register - Security

Japan's digital minister surrenders salary to say sorry for data leaks

August 17th 2023 at 04:58

The My Number card mess remains unsolved as trust in e-government remains muted

Japan’s digital minister has doubled down on a June promise to penalize himself for the poor rollout of the country’s digital ID, My Number Card, by offering up three months salary on Tuesday.…

☐ β˜† βœ‡ The Register - Security

Vietnam admits it has just ten percent of the infosec pros it needs

August 17th 2023 at 02:59

Which is a problem, because local orgs are leaking data and shadowy traders are cashing in

Vietnam’s Ministry of Information and Communications has admitted the nation has a vast shortfall of infosec pros.…

☐ β˜† βœ‡ The Register - Security

Discord.io pulls the cord after crooks steal 760K users' info

August 16th 2023 at 22:58

Cleanup will involve 'complete rewrite of our website's code'

Discord.io has shut down "for the foreseeable future," after crooks stole, and then put up for sale, data belonging to all 760,000 of the service's users.…

☐ β˜† βœ‡ The Register - Security

Clorox cleans up IT security breach that soaked its biz ops

August 15th 2023 at 22:22

Plus: Medical records for 4M people within reach of Clop gang after IBM MOVEit deployment hit

The Clorox Company has some cleaning up to do as some of its IT systems remain offline and operations "temporarily impaired" following a security breach.…

☐ β˜† βœ‡ The Register - Security

Ensure data security at the edge

August 15th 2023 at 12:16

Why a fully mobile, hybrid and edge workforce needs a more flexible security solution

Sponsored Feature Securing the corporate network has never been a simple process, but years ago it was at least a bit more straightforward. Back then, the network perimeter was clear and well defined, and everything inside itΒ was considered trusted and safe. The security team defended against everything outside, established security protocols and deployed security tools, monitored the network gateways, and kept sensitive data as safe as possible.…

☐ β˜† βœ‡ The Register - Security

You're not seeing double – yet another UK copshop is confessing to a data leak

August 15th 2023 at 11:28

Norfolk and Suffolk constabularies admit to accidentally including raw crime data in FoI responses

Norfolk and Suffolk police have stepped forward to admit that a β€œtechnical issue” resulted in raw data pertaining to crime reports accidentally being included in Freedom of Information responses.…

☐ β˜† βœ‡ The Register - Security

Tech CEO admits role in tricking Qualcomm into $150M takeover

August 15th 2023 at 10:27

Abreezio? Maybe not, but it was a plea deal

The former chief executive of a company that was sold to Qualcomm for more than $150 million has pleaded guilty to one count of money laundering relating to a $1.5 million transaction involving proceeds from the deal.…

☐ β˜† βœ‡ The Register - Security

Florida Man and associates indicted for conspiracy to steal data, software

August 15th 2023 at 06:58

Voting machines and their info allegedly accessed without authorization by keen golfer's gofers

Authorities in the US state of Georgia have indicted a famous Floridian and his loyal associates on counts including theft of data, software, and personal information.…

☐ β˜† βœ‡ The Register - Security

Chinese media teases imminent exposΓ© of seismic US spying scheme

August 15th 2023 at 01:57

Again labels America a hacker empire over alleged backdoors found in earthquake monitoring kit

China's Global Times, a state-controlled media outlet, has teased an imminent exposΓ© of alleged US attacks on seismic data measurement stations.…

☐ β˜† βœ‡ The Register - Security

Sextortion suspects on trial after teen victim dies from a self-inflicted gunshot wound

August 14th 2023 at 23:28

Trio alleged to have blackmailed over 100 targets after threats of intimate image release

Two Nigerian men have been extradited to the US and were scheduled to appear in deferral court on Monday, charged with sextortion and causing the death of one of their victims: a teen who was found dead from a self-inflicted gunshot wound.…

☐ β˜† βœ‡ The Register - Security

Beware cool-looking beta crypto-apps. They may be money-stealing fakes

August 14th 2023 at 22:22

Try out a hot new thing before official launch? Something smells phishy

The FBI has warned of a scam in which criminals lure people into installing what they think are pre-release beta-grade phone apps to try out – only for the software to be laced with malware.…

☐ β˜† βœ‡ The Register - Security

Ford SYNC 3 infotainment vulnerable to drive-by Wi-Fi hijacking

August 14th 2023 at 20:48

Don't panic, says automaker, but if you do, just turn off wireless for now

Ford has suggested owners of vehicles equipped with its SYNC 3 infotainment system disable the Wi-Fi lest someone nearby exploits a buffer-overflow vulnerability and hijacks the equipment.…

☐ β˜† βœ‡ The Register - Security

Cumbrian Police accidentally publish all officers' details online

August 14th 2023 at 11:38

Names, job titles and salaries included in unwitting leak

Cumbria Constabulary inadvertently published the names and salaries of all its officers and staff online earlier this year, making it the second UK force in a fortnight to admit disclosing personal information about its employees.…

☐ β˜† βœ‡ The Register - Security

Hacktivists attack Japanese government over Fukushima wastewater release

August 14th 2023 at 05:58

Claiming affiliation with Anonymous, e-hippies want more debate over radioactive flows

Entities using the name and iconography of Anonymous (EUTNAIOA) claim to have conducted cyber protests against the Japanese government for actions related to the release of wastewater from the Fukushima Daini Nuclear Power Plant.…

☐ β˜† βœ‡ The Register - Security

US government to investigate China's Microsoft email breach

August 14th 2023 at 02:58

PLUS: Phishing campaign targets the C-suite; Cybercrime arrests in EU and Africa; and more

Infosec in brief The July breach of Microsoft Exchange Online by suspected Chinese hackers is the next topic up for review by the Department of Homeland Security's Cyber Safety Review Board (CSRB). …

☐ β˜† βœ‡ The Register - Security

Google Chrome to shield encryption keys from promised quantum computers

August 12th 2023 at 10:27

QC crypto-cracking coming in 5, 10, maybe 50 years, so act … now?

Google has started deploying a hybrid key encapsulation mechanism (KEM) to protect the sharing of symmetric encryption secrets during the establishment of secure TLS network connections.…

☐ β˜† βœ‡ The Register - Security

FTX crypto-clown Sam Bankman-Fried couldn't even do house arrest. Now he's in jail

August 11th 2023 at 22:15

Feds argue leaks to press amount to witness tampering

Sam Bankman-Fried (SBF), former chief executive of crypto-disaster FTX, who has been awaiting trial for his firm's failure while in home detention with his family, has been sent to jail for attempting to intimidate witnesses.…

☐ β˜† βœ‡ The Register - Security

Microsoft: Codesys PLC bugs could be exploited to 'shut down power plants'

August 11th 2023 at 19:40

What are these gadgets running, Windows? Ka-boom-tsch

Fifteen bugs in Codesys' industrial control systems software could be exploited to shut down power plants or steal information from critical infrastructure environments, experts have claimed.…

☐ β˜† βœ‡ The Register - Security

Maker of Chrome extension with 300,000+ users tells of constant pressure to sell out

August 11th 2023 at 17:29

Anyone with sizable audience in this surveillance economy is invited to stuff their add-ons with tracking and ads

Interview In the past nine years, Oleg Anashkin, a software developer based in San Jose, California, has received more than 130 solicitations to monetize his Chrome browser extension, Hover Zoom+.…

☐ β˜† βœ‡ The Register - Security

Electoral Commission had internet-facing server with unpatched vuln

August 11th 2023 at 11:47

ProxyNotShell vulnerability could be how UK body got pwned, suggests infosec expert

The hacking of the UK’s Electoral Commission was potentially facilitated by the exploitation of a vulnerability in Microsoft Exchange, according to a security expert.…

☐ β˜† βœ‡ The Register - Security

Magento shopping cart attack targets critical vulnerability revealed in early 2022

August 11th 2023 at 10:23

Really? You didn't bother to patch a 9.8 severity critical flaw?

Ecommerce stores using Adobe's open source Magento 2 software are being targeted by an ongoing exploitation campaign based on a critical vulnerability that was patched last year, on February 13, 2022.…

☐ β˜† βœ‡ The Register - Security

US Cyber Command boss says China's spooky cyber skills still behind

August 11th 2023 at 05:27

Paul Nakasone rates the Middle Kingdom a 'pacing challenge'

The boss of US Cyber Command has opined that China's cyber and surveillance capabilities are not ahead of, or even comparable to, to those of the United States.…

☐ β˜† βœ‡ The Register - Security

There's a good chance your VPN is vulnerable to privacy-menacing TunnelCrack attack

August 10th 2023 at 20:37

Especially on Apple gear, uni team says

A couple of techniques collectively known as TunnelCrack can, in the right circumstances, be used by snoops to force victims' network traffic to go outside their encrypted VPNs, it was demonstrated this week.…

☐ β˜† βœ‡ The Register - Security

Get your staff's consent before you monitor them, tech inquiry warns

August 10th 2023 at 10:00

Plus: British government's push to reform data protection is working against the cause

Companies that monitor their employees should only do so after they consult with and get consent from the staffers they are watching or tracking.…

☐ β˜† βœ‡ The Register - Security

Nearly every AMD CPU since 2017 vulnerable to Inception data-leak attacks

August 9th 2023 at 22:52

It's like a nesting doll of security flaws

AMD processor users, you have another data-leaking vulnerability to deal with: like Zenbleed, this latest hole can be to steal sensitive data from a running vulnerable machine.…

☐ β˜† βœ‡ The Register - Security

Rapid7 prepares to toss 18% of workforce to cut costs

August 9th 2023 at 18:00

Operating expenses almost as high as actual turnover in latest quarterly numbers

Rapid7 is initiating a restructuring process that will involve shedding 18 percent of its workforce after net losses widened over the most recent quarter.…

☐ β˜† βœ‡ The Register - Security

Northern Ireland police may have endangered its own officers by posting details online in error

August 9th 2023 at 13:00

At least it was a blunder and not a hostile attack, unlike what happened to another UK public body this week

A spreadsheet containing details of serving Northern Ireland police officers was mistakenly posted online yesterday, potentially endangering the safety of officers, given the volatile politics of the region.…

☐ β˜† βœ‡ The Register - Security

INTERPOL shutters '16shop' phishing-as-a-service outfit

August 9th 2023 at 03:02

Alleged administrator cuffed in Indonesia, associate arrested in Japan, accused of selling fake Amazons for $60

INTERPOL has revealed a successful investigation into a phishing-as-a-service operation named "16shop" with arrests of alleged operators made in Indonesia and Japan and the platform shut down.…

☐ β˜† βœ‡ The Register - Security

Microsoft, Intel lead this month's security fix emissions

August 8th 2023 at 23:18

Downfall processor leaks, Teams holes, VPN clients at risk, and more

Patch Tuesday Microsoft's August patch party seems almost boring compared to the other security fires it's been putting out lately.…

☐ β˜† βœ‡ The Register - Security

Cyber-extortionists pillage Colorado education dept

August 8th 2023 at 19:19

Hey, breacher, leave those kids alone

Data going back as far as nearly 20 years may have been stolen from the Colorado Department of Higher Education (CDHE) after ransomware extortionists breached the government body's IT systems.…

☐ β˜† βœ‡ The Register - Security

UK voter data within reach of miscreants who hacked Electoral Commission

August 8th 2023 at 15:52

'It doesn't help if the organization responsible for the integrity of elections' gets pwned

The IT infrastructure of the UK's Electoral Commission was broken into by miscreants, who will have had access to names and addresses of voters, as well as the election oversight body's email and unspecified other systems.…

☐ β˜† βœ‡ The Register - Security

China – which surveils everyone everywhere – floats facial recognition rules

August 8th 2023 at 10:39

Regulator says with a straight face that it should not be allowed to analyze ethnicity

China has released draft regulations to govern the country's facial recognition technology that include prohibitions on its use to analyze race or ethnicity.…

☐ β˜† βœ‡ The Register - Security

North Korean hackers had access to Russian missile maker for months, say researchers

August 8th 2023 at 06:27

Kim Jong Un's cyber-goons aren't above attacking the regime's few friends

Two North Korean hacker groups had access to the internal systems of Russian missile and satellite developer NPO Mashinostoyeniya for five to six months, cyber security firm SentinelOne asserted on Monday. The attack illustrates potential North Korean efforts to advance development of missile and other military tech via cyber espionage.…

☐ β˜† βœ‡ The Register - Security

Stalkerware slinger LetMeSpy shuts down for good after database robbery

August 7th 2023 at 21:12

If you can't trust a spyware developer with your info, who can you trust?

Stalkerware slinger LetMeSpy will shut down for good this month after a miscreant breached its servers and stole a heap of data in June.…

☐ β˜† βœ‡ The Register - Security

Microsoft hits back at Tenable criticism of its infosec practices

August 7th 2023 at 05:40

'Not all fixes are equal,' argues Redmond, and this one for the Power Platform didn't need to be rushed

Microsoft has explained why it seemingly took its time to fix a flaw reported to it by infosec intelligence vendor Tenable.…

☐ β˜† βœ‡ The Register - Security

Five Eyes nations detail dirty dozen most exploited vulnerabilities

August 7th 2023 at 03:03

PLUS: FBI admits buying NSO spyware; "IT" company busted for drugs 'n guns biz; this week's critical vulns

Infosec in brief If you're wondering what patches to prioritize, ponder no longer: An international group of cybersecurity agencies has published a list of the 12 most commonly exploited vulnerabilities of 2022 – a list many will recognize. …

☐ β˜† βœ‡ The Register - Security

Two US Navy sailors charged with giving Chinese spies secret military info

August 4th 2023 at 22:03

'Quite obviously f**king espionage,' one suspect allegedly blabbed

Two US Navy service members appeared in federal court Thursday accused of espionage and stealing sensitive military information for China in separate cases.…

☐ β˜† βœ‡ The Register - Security

Alarm raised over Mozilla VPN: Wonky authorization check lets users cause havoc

August 4th 2023 at 19:48

SUSE security engineer goes public on unfixed client hole after disclosure drama

Updated A security engineer at Linux distro maker SUSE has published an advisory for a flaw in the Mozilla VPN client for Linux that has yet to be addressed in a publicly released fix because the disclosure process went off the rails.…

☐ β˜† βœ‡ The Register - Security

Couple admit they laundered $4B in stolen Bitcoins after Bitfinex super-heist

August 4th 2023 at 01:11

A man, a plan, and Razzlekhan fought the law – and the law won

Ilya Lichtenstein and Heather Morgan on Thursday pleaded guilty to money-laundering charges related to the 2016 theft of some 120,000 Bitcoins from Hong Kong-based Bitfinex.…

☐ β˜† βœ‡ The Register - Security

Russia's Cozy Bear is back and hitting Microsoft Teams to phish top targets

August 3rd 2023 at 21:24

Plus: Tenable CEO blasts Redmond's bug disclosure habits

An infamous Kremlin-backed gang has been using Microsoft Teams chats in attempts to phish marks in governments, NGOs, and IT businesses, according to the Windows giant.…

☐ β˜† βœ‡ The Register - Security

Old-school hacktivism is back because it never went away

August 3rd 2023 at 19:44

Mysterious Team Bangladesh has carried out 846 attacks since June 2022, mostly DDoS

Hacktivism may have dropped off of organization radars over the past few years, but it is now very visibly coming from what is believed to be Bangladesh, thanks to a group tracked by cybersecurity firm Group-IB.…

☐ β˜† βœ‡ The Register - Security

Brit healthcare body rapped for WhatsApp chat sharing patient data

August 3rd 2023 at 09:26

Time for a proper secure clinical image transfer system, perhaps?

Staff at NHS Lanarkshire - which serves over half a million Scottish residents - used WhatsApp to swap photos and personal info about patients, including children's names and addresses.…

☐ β˜† βœ‡ The Register - Security

Prepare for plenty more pain from Ivanti's MDM flaws, warn cyber agencies

August 3rd 2023 at 07:38

Invaders already spent four or more months frolicking inside Norwegian government servers

Intruders who exploited a critical Ivanti bug to compromise 12 Norwegian government agencies spent at least four months looking around the organizations' systems and stealing data before the intrusion was discovered and stopped.…

☐ β˜† βœ‡ The Register - Security

Australian Senate committee recommends bans on Chinese social media apps

August 2nd 2023 at 06:30

WeChat accused of 'contempt for Parliament' as transparency rules floated for platforms

An Australian Senate Committee has recommended banning Chinese social media apps in the land down under, on grounds the Communist Party of China uses them to spread propaganda and misinformation.…

☐ β˜† βœ‡ The Register - Security

Socket moves beyond JavaScript and Python and gets into Go

August 2nd 2023 at 01:58

CEO, fresh with funds, lays out the dependency dilemma

Interview Open source security biz Socket is extending its source code dependency checker, which previously addressed only JavaScript and Python, by adding support for checking Go code.…

☐ β˜† βœ‡ The Register - Security

Bad news: Another data-leaking CPU flaw. Good news: It's utterly impractical

August 1st 2023 at 17:00

Collide+Power vulnerability leaks secrets bit by bit - but could take months or years to learn a useful secret

Boffins in Austria and Germany have devised a power-monitoring side-channel attack on modern computer chips that exposes sensitive data, but very slowly.…

❌