FreshRSS

πŸ”’
☐ β˜† βœ‡ The Register - Security

Cryptojackers spread their nets to capture more than just EC2

September 18th 2023 at 11:15

AMBERSQUID operation takes AWS's paths less travelled in search of compute

As cloud native computing continues to gain popularity, so does the risk posed by criminals seeking to exploit the unwary. One newly spotted method targets services on the AWS platform, but not necessarily the ones you might think.…

☐ β˜† βœ‡ The Register - Security

Probe reveals previously secret Israeli spyware that infects targets via ads

September 16th 2023 at 09:05

Oh s#!t, Sherlock

Israeli software maker Insanet has reportedly developed a commercial product called Sherlock that can infect devices via online adverts to snoop on targets and collect data about them for the biz's clients.…

☐ β˜† βœ‡ The Register - Security

Scattered Spider traps 100+ victims in its web as it moves into ransomware

September 15th 2023 at 21:25

Mandiant warns casino raiders are doubling down on 'monetization strategies'

Scattered Spider, the crew behind at least one of the recent Las Vegas casino IT security breaches, has already hit some 100 organizations during its so-far brief tenure in the cybercrime scene, according to Mandiant.…

☐ β˜† βœ‡ The Register - Security

Google throws California $93M to make location tracking lawsuit disappear

September 15th 2023 at 17:15

Half a percent of last quarter's net income? That'll teach 'em

Google has been hit with another lawsuit alleging it deceived users about its collection, storage, and use of their location data, this time from the state of California.Β Yet it's over before it really began.…

☐ β˜† βœ‡ The Register - Security

Greater Manchester Police ransomware attack another classic demo of supply chain challenges

September 15th 2023 at 09:45

Are you the weakest link?

The UK's Greater Manchester Police (GMP) has admitted that crooks have got their mitts on some of its data after a third-party supplier responsible for ID badges was attacked.…

☐ β˜† βœ‡ The Register - Security

US-Canada water org confirms 'cybersecurity incident' after ransomware crew threatens leak

September 15th 2023 at 00:15

NoEscape promises 'colossal wave of problems' if IJC doesn't pay up

The International Joint Commission, a body that manages water rights along the US-Canada border, has confirmed its IT security was targeted, after a ransomware gang claimed it stole 80GB of data from the organization.…

☐ β˜† βœ‡ The Register - Security

Caesars says cyber-crooks stole customer data as MGM casino outage drags on

September 14th 2023 at 20:13

Zero-days are so 2022. Why not just social engineer the help desk?

Updated Casino giant Caesars Entertainment has confirmed miscreants stole a database containing customer info, including driver license and social security numbers for a "significant number" of its loyalty program members, in a social engineering attack earlier this month.…

☐ β˜† βœ‡ The Register - Security

Rollbar might be good at tracking bugs, uninvited guests not so much

September 14th 2023 at 15:00

Company noticed data warehouse break-in via compromised account a month later

Cloud-based bug tracking and monitoring platform Rollbar has warned users that attackers have rifled through their data.…

☐ β˜† βœ‡ The Register - Security

Watchdog urges change of HART: Late, expensive US biometric ID under fire

September 13th 2023 at 20:00

Homeland Security told to mind costs, fix up privacy controls

Twice delayed and over budget, the US Department of Homeland Security (DHS) has been told by the Government Accountability Office (GAO) that it needs to correct shortcomings in its biometric identification program.…

☐ β˜† βœ‡ The Register - Security

Uncle Sam warns deepfakes are coming for your brand and bank account

September 13th 2023 at 18:30

No, your CEO is not on Teams asking you to transfer money

Deepfakes are coming for your brand, bank accounts, and corporate IP, according to a warning from US law enforcement and cyber agencies.…

☐ β˜† βœ‡ The Register - Security

Airbus suffers data leak turbulence to cybercrooks' delight

September 13th 2023 at 17:45

Ransomware group nicked info from employee of airline, say researchers

Aerospace giant Airbus has fallen victim to a data breach, thanks in part to the inattention of a third party.…

☐ β˜† βœ‡ The Register - Security

Used cars? Try used car accounts: 15,000 up for grabs online at just $2 a pop

September 13th 2023 at 12:15

Cut and shut is so last century, now it's copy and clone

Researchers have found almost 15,000 automotive accounts for sale online and pointed at a credential-stuffing attack that targeted car makers.…

☐ β˜† βœ‡ The Register - Security

How to snoop on passwords with this one weird trick (involving public Wi-Fi signals)

September 13th 2023 at 10:45

Fun technique – but how practical is it?

Some smart cookies at institutions in China and Singapore have devised a technique for reading keystrokes and pilfering passwords or passcodes from Wi-Fi-connected mobile devices on public networks, without any hardware hacking.…

☐ β˜† βœ‡ The Register - Security

Capita class action: 2,000 folks affected by data theft sign up

September 13th 2023 at 10:02

Pensioners, employees and medical pros among those aiming to be compensated for data exposure

The number of claimants signing up to a collective action against Capita over the infamous March cyber security break-in and subsequent data exposure keeps going up, according to the lawyer overseeing the case.…

☐ β˜† βœ‡ The Register - Security

Ransomware attack hits Sri Lanka government, causing data loss

September 13th 2023 at 03:48

Running unsupported and unpatched versions of Exchange Server will do that to a country

Sri Lanka's Computer Emergency Readiness Team (CERT) is currently investigating a ransomware attack on the government's cloud infrastructure that affected around 5,000 email accounts, it revealed on Tuesday.…

☐ β˜† βœ‡ The Register - Security

China caught – again – with its malware in another nation's power grid

September 12th 2023 at 23:59

'Obtaining a disruptive capability could be one possible motivation behind this surge in attacks'

Espionage-ware thought to have been developed by China has once again been spotted within the power grid of a neighboring nation.…

☐ β˜† βœ‡ The Register - Security

Grab those updates: Microsoft flings out fixes for already-exploited bugs

September 12th 2023 at 21:13

Plus: Adobe and Android also tackle abused-in-the-wild flaws

Patch Tuesday It's every Windows admin's favorite day of the month: Patch Tuesday. Microsoft emitted 59 patches for its September update batch, including two for bugs that have already been exploited.…

☐ β˜† βœ‡ The Register - Security

OpenSSL 1.1.1 reaches end of life for all but the well-heeled

September 12th 2023 at 18:00

$50k to breathe new life into its corpse. The rest of us must move on to OpenSSL 3.0

OpenSSL 1.1.1 has reached the end of its life, making a move to a later version essential for all, bar those with extremely deep pockets.…

☐ β˜† βœ‡ The Register - Security

Chrome, Firefox and more caught with their WebP down, offer hasty patch-up

September 12th 2023 at 15:00

Exploit observed in the wild against codec lib in browsers, apps

Updated Google and Mozilla have rushed out a fix for a vulnerability within their browsers – Chrome and Firefox, respectively – noting an exploit already exists in the wild.…

☐ β˜† βœ‡ The Register - Security

Save the Children hit by ransomware, 7TB stolen

September 11th 2023 at 22:21

A new low, even for these lowlifes

Updated Cybercrime crew BianLian says it has broken into the IT systems of a top nonprofit and stolen a ton of files, including what the miscreants claim is financial, health, and medical data.…

☐ β˜† βœ‡ The Register - Security

MGM Resorts shuts down website, computer systems after 'cybersecurity incident'

September 11th 2023 at 20:17

Ransomware? Some would be willing to bet on that

MGM Resorts has shut down some of its IT systems following a "cybersecurity incident" that the casino-and-hotel giant says is currently under investigation.…

☐ β˜† βœ‡ The Register - Security

Huge DDoS attack against US financial institution thwarted

September 11th 2023 at 18:46

Akamai reckons traffic flood peaked atΒ 55.1 million packets per second

Akamai says it thwarted a major distributed denial-of-service (DDoS) attack aimed at a US bank that peaked atΒ 55.1 million packets per second earlier this month.…

☐ β˜† βœ‡ The Register - Security

Google warns infoseccers: Beware of North Korean spies sliding into your DMs

September 11th 2023 at 00:32

ALSO: Verizon turns self in for reduced fine, malvertising comes to macOS, and this week's critical vulnerabilities

Infosec in brief Watch out, cyber security researchers: Suspected North Korean-backed hackers are targeting members of the infosec community again, according to Google's Threat Analysis Group (TAG).…

☐ β˜† βœ‡ The Register - Security

Apple races to patch the latest zero-day iPhone exploit

September 8th 2023 at 11:36

No user interaction needed for this one as Pegasus turns up via iMessage

Apple devices are again under attack, with a zero-click, zero-day vulnerability used to deliver Pegasus spyware to iPhones discovered in the wild.…

☐ β˜† βœ‡ The Register - Security

Microsoft, recently busted by Beijing, thinks it's across China's ever-changing cyber-offensive

September 8th 2023 at 06:32

Sometimes using AI to make hilariously wrong images that still drive social media engagement

Microsoft, which earlier this week admitted not being able to detect a Chinese attack on its own infrastructure, has published a report [PDF] titled "Digital threats from East Asia increase in breadth and effectiveness." In the report, Redmond's Threat Intelligence group expounds on its fresh insight into evolving online aggressions from both China and North Korea.…

☐ β˜† βœ‡ The Register - Security

Russian infosec boss gets nine years for $100M insider-trading caper using stolen data

September 8th 2023 at 00:57

Confidential figures for Tesla, Snap, Roku, Avnet, others swiped and used to rack up millions in ill-gotten gains

Vladislav Klyushin, the Russian owner of security penetration testing firm M-13, was jailed for nine years in the US on Thursday for his involvement in a cyber-crime operation that stole top corporations' confidential financial information to make $93 million through insider trading.…

☐ β˜† βœ‡ The Register - Security

US, UK sanction more Russians linked to Trickbot

September 7th 2023 at 22:44

Top admin, HR managers, devs go on transatlantic deny-list

The US and UK governments named and sanctioned 11 Russians said to be connected to the notorious Trickbot cybercrime crew this week.…

☐ β˜† βœ‡ The Register - Security

Lawsuit claims Tesla corp data security is far less advanced than its cars

September 7th 2023 at 16:30

Sueball alleges company at fault after employee info leaked, including Musk's

An ex-Tesla staffer has filed a proposed class action lawsuit that blames poor access control at the carmaker for a data leak, weeks after Tesla itself sued the alleged leakers, two former employees.…

☐ β˜† βœ‡ The Register - Security

If you like to play along with the illusion of privacy, smart devices are a dumb idea

September 7th 2023 at 12:11

You're just giving manufacturers carte blanche to profit off personal data

Updated Depressingly predictable research from Which? serves as another reminder, if one was needed, that furnishing your home with internet-connected "smart" devices could be a dumb idea if you'd rather try to preserve your privacy.…

☐ β˜† βœ‡ The Register - Security

UK drops 'spy clause' for scanning encrypted chat, admits it's not 'feasible'

September 7th 2023 at 10:09

But don't celebrate yet ... it has simply kicked the online safety can down the road, Westminster style

Comment Sanity appears to have prevailed in the debate over the UK's Online Safety Bill after the government agreed to ditch proposals – at least for the time being – to legislate the scanning of end-to-end encrypted messages.…

☐ β˜† βœ‡ The Register - Security

China reportedly bans iPhones from more government offices

September 7th 2023 at 05:28

So what? Smartphones are routinely restricted in, or excluded from, sensitive locations

Analysis Chinese authorities have reportedly banned Apple's iPhones from some government offices.…

☐ β˜† βœ‡ The Register - Security

Microsoft: China stole secret key that unlocked US govt email from crash debug dump

September 6th 2023 at 22:59

Mistakes were made, lessons learned, stuff now fixed, says Windows maker

Remember that internal super-secret Microsoft security key that China stole and used to break into US government email accounts back in July? …

☐ β˜† βœ‡ The Register - Security

Guy who ran Bitcoins4Less tells Feds he had less than zero laundering protections

September 6th 2023 at 20:42

What? Yogurt Monster isn't really a legitimate customer's name?!

A California man has admitted he failed to bake anti-money laundering protections into his cryptocurrency exchange, thus allowing scammers and drug traffickers to launder millions of dollars through the service.…

☐ β˜† βœ‡ The Register - Security

Coffee Meets Bagel outage caused by cybercriminals deleting data and files

September 6th 2023 at 16:01

Did you potentially miss the love match of your life in week-long blackout? Nope, nobody could access it

If you got snubbed by the object of your affections on dating app Coffee Meets Bagel (CMB) in late August, don't feel bad, the company says its systems were down due to cyber baddies.…

☐ β˜† βœ‡ The Register - Security

Meatbag mishaps more menacing than malware? CISOs think so

September 6th 2023 at 13:20

Company boards, on the other hand, aren't letting cybersecurity disturb their sleep as much

Chief information security officers (or CISOs) see human error as the most significant risk to data protection compared to other UK board directors.…

☐ β˜† βœ‡ The Register - Security

You patched yet? Years-old Microsoft security holes still hot targets for cyber-crooks

September 5th 2023 at 21:37

We're number one! We're number one! We're...

It's generally accepted that security flaws in Microsoft's products are a top magnet for crooks and fraudsters: its sprawling empire of hardware and software is a target-rich ecosystem in that there is a wide range of bugs to exploit, and a huge number of vulnerable organizations and users.…

☐ β˜† βœ‡ The Register - Security

Big Tech has failed to police Russian disinformation, EC study concludes

September 5th 2023 at 17:45

In Putin's Russia, the planet hacks you

The power of the EU's Digital Services Act (DSA) to actually police the world's very large online platforms (VLOPs) has been tested in a new study focused on Russian social media disinformation.…

☐ β˜† βœ‡ The Register - Security

Freecycle gives users the gift of a security breach notice

September 5th 2023 at 14:24

Change your passwords. And maybe give the recycling a miss this time

Updated Freecycle, the charity aimed at recycling detritus that would otherwise be headed for landfill, has become the latest organization to suffer at the hands of cyber attackers and admit to a breach.…

☐ β˜† βœ‡ The Register - Security

Northern Ireland's top cop quits after security breach, disciplinary controversy

September 5th 2023 at 11:45

Simon Byrne faced backlash over FoI blunder, plus claims officers were 'punished' to appease Sinn FΓ©in

Northern Ireland's police chief, Simon Byrne, resigned last night after an emergency meeting of the Policing Board amid discontent in the rank and file over a data breach that exposed serving officers' info, as well as news he was considering appealing a court ruling linked to the Troubles.…

☐ β˜† βœ‡ The Register - Security

Attackers accessed UK military data through high-security fencing firm's Windows 7 rig

September 4th 2023 at 15:25

Irony, not barbed wire, cuts the deepest

The risk of running obsolete code and hardware was highlighted after attackers exfiltrated data from a UK supplier of high-security fencing for military bases. The initial entry point? A Windows 7 PC.…

☐ β˜† βœ‡ The Register - Security

Microsoft calls time on ancient TLS in Windows, breaking own stuff in the process

September 4th 2023 at 14:15

Hold onto your SQL Server, enterprise admins

Microsoft has reminded users that TLS 1.0 and 1.1 will soon be disabled by default in Windows.…

☐ β˜† βœ‡ The Register - Security

Tsunami watch

September 4th 2023 at 14:08

Mitigating the threat of bot-driven DDoS attacks

Webinar It's sometimes easy to be lulled into a sense of false security and imagine that your organization or business will not become a target of highly professional cybercriminals, hacktivists and even nation-state actors. But the threat posed by DDoS attacks is very much on the rise.…

☐ β˜† βœ‡ The Register - Security

Northern Irish cops release 2 men after Terrorism Act arrests linked to data breach

September 4th 2023 at 12:33

Came in wake of the force publishing their own people's data in botched FoI

Nearly four weeks after the Police Service of Northern Ireland (PSNI) published data on 10,000 employees in a botched response to a Freedom of Information request, another two men, aged 21 and 22, have been released on bail after being arrested under the Terrorism Act.…

☐ β˜† βœ‡ The Register - Security

Apple opens annual applications for free hackable iPhones

September 4th 2023 at 02:58

ALSO: Brazilian stalkerware database ripped by the short hairs, a fast fashion breach, and this week's critical vulns

Infosec in brief The latest round of Apple's Security Research Device (SRD) program is open, giving security researchers a chance to get their hands on an unlocked device – and Apple's blessing to attack it and test its security capabilities.…

☐ β˜† βœ‡ The Register - Security

Cops drill into chat apps, sink plot to smuggle tonnes of coke into Europe

September 2nd 2023 at 07:55

Big blow to blighters' blow-by-the-boatload blueprint

Video Efforts by cops to seize and shut down encrypted messaging apps favored by criminals, and then mine their conversations for evidence, appear to have led to more arrests β€” plus the seizure of about 2.7 tonnes of cocaine.…

☐ β˜† βœ‡ The Register - Security

More Okta customers trapped in Scattered Spider's web

September 1st 2023 at 19:15

Oktapus phishing campaign criminals are back in action

Customers of cloudy identification vendor Okta are reporting social engineering attacks targeting their IT service desks in attempts to compromise user accounts with administrator permissions.…

☐ β˜† βœ‡ The Register - Security

Massive attack

September 1st 2023 at 13:34

Defeating a DDoS swarm

Webinar Any organization can lose service, revenue, and reputation as a result. If you are particularly unlucky, a DDoS attack can defenestrate your network defences. You may find yourself facing an cyber criminal who wants to take your business for everything it's got - not an attractive prospect in anybody's book.…

☐ β˜† βœ‡ The Register - Security

Good news for Key Group ransomware victims: Free decryptor out now

August 31st 2023 at 22:47

That's what we call a static shock

Even ransomware operators make mistakes, and in the case of ransomware gang the Key Group, a cryptographic error allowed a team of security researchers to develop and release a decryption tool to restore scrambled files.…

☐ β˜† βœ‡ The Register - Security

Kremlin-backed Sandworm strikes Android devices with data-stealing Infamous Chisel

August 31st 2023 at 19:13

Five Eyes nations warn of hit against Ukrainian military systems

Russia's Sandworm crew is using an Android malware strain dubbed Infamous Chisel to remotely access Ukrainian soldiers' devices, monitor network traffic, access files, and steal sensitive information, according to a Five Eyes report published Thursday.…

☐ β˜† βœ‡ The Register - Security

Barracuda gateway attacks: How Chinese snoops keep a grip on victims' networks

August 30th 2023 at 23:00

Backdoors detailed, plus CISA releases more IOCs for IT depts to check

Nearly a third of organizations compromised by Chinese cyberspies via a critical bug in some Barracuda Email Security Gateways were government units, according to Mandiant.…

☐ β˜† βœ‡ The Register - Security

Microsoft ain't happy with Russia-led UN cybercrime treaty

August 30th 2023 at 18:23

Could be used to put ethical hackers, and citizens, behind bars

A controversial United Nations proposal has a new foe, Microsoft, which has joined the growing number of organizations warning delegates that the draft version of the UN cybercrime treaty only succeeds in justifying state surveillance β€” not stopping criminals, as originally intended.…

☐ β˜† βœ‡ The Register - Security

Toyota Japan back on the road after probably-not-cyber attack halted production

August 30th 2023 at 03:58

Malfunction took 14 plants offline for 36 hours. Oh, what a … nah, too obvious

Toyota Japan has recovered from what it's described as a "malfunction in the production order system" that halted production on 28 lines across 14 plants starting on Monday evening.…

☐ β˜† βœ‡ The Register - Security

Meta reckons China's troll farms could learn proper OpSec from Russia's fake news crews

August 30th 2023 at 00:58

Claims to have taken down two colossal networks, with 'Secondary Infektion' schooling 'Spamouflage'

Russia appears to be "better" at running online trolling campaigns aimed at pushing its political narratives than China, according to Meta's latest Adversarial Threat Report.…

☐ β˜† βœ‡ The Register - Security

University cuts itself off from internet after mystery security snafu

August 29th 2023 at 21:37

Halls of learning are stuck offline, but go Wolverines!

Updated The University of Michigan has isolated itself from the internet but, hey, everything's fine!…

☐ β˜† βœ‡ The Register - Security

Apple security boss faces iPads-for-gun-permits bribery charge... again

August 29th 2023 at 20:32

'We will continue fighting this case' global chief's lawyer tells us

An appeals court has reversed a 2021 decision to drop a bribery charge against Apple's head of global security, who is accused of donating iPads worth up to $80,000 to a sheriff's office in exchange for giving his Cupertino agents concealed carry weapon licenses.…

☐ β˜† βœ‡ The Register - Security

FBI-led Operation Duck Hunt shoots down Qakbot

August 29th 2023 at 20:03

Totally plucked: Agents remotely roast Windows botnet malware on victims' machines

Uncle Sam today said an international law enforcement effort dismantled Qakbot, aka QBot, a notorious botnet and malware loader responsible for losses totaling hundreds of millions of dollars worldwide, and seized more than $8.6 million in illicit cryptocurrency.…

☐ β˜† βœ‡ The Register - Security

More UK cops' names and photos exposed in supplier breach

August 29th 2023 at 11:35

All 47,000 Met Police officers and staff reportedly accessed in break-in

London's Metropolitan Police has said a third-party data breach exposed staff and officers' names, ranks, photos, vetting levels, and salary information.…

☐ β˜† βœ‡ The Register - Security

Health, payment info for 1.2M people feared stolen from Purfoods in IT attack

August 28th 2023 at 21:45

Meal delivery biz leaves bitter taste

Purfoods has notified more than 1.2 million people that their personal and medical data β€”Β including payment card and bank account numbers, security codes, and some protected health information β€” may have been stolen from its servers during what sounds like a ransomware infection earlier this year.…

☐ β˜† βœ‡ The Register - Security

Malware loader lowdown: The big 3 responsible for 80% of attacks so far this year

August 28th 2023 at 16:30

Top of the list to trip sensors

Three malware loaders β€” QBot, SocGholish, and Raspberry Robin β€” are responsible for 80 percent of observed attacks on computers and networks so far this year.…

☐ β˜† βœ‡ The Register - Security

Whiffy malware stinks after tracking location via Wi-FI

August 28th 2023 at 05:15

ALSO: Euro chip maker breached, crims plan to undermine cyber insurance, and this week's critical vulnerabilities

Infosec in Brief No one likes malware, but malicious code that tracks your location is particularly unlovable.…

❌