FreshRSS

πŸ”’
☐ β˜† βœ‡ The Register - Security

MGM Resorts attackers hit personal data jackpot, but house lost $100M

October 6th 2023 at 15:30

Racecars and cyber insurance will balance its books in no time, though

MGM Resorts has admitted that the cyberattack it suffered in September will likely cost the company at least $100 million.…

☐ β˜† βœ‡ The Register - Security

CDW data to be leaked next week after negotiations with LockBit break down

October 6th 2023 at 13:21

Ransomware spokesperson scoffs at IT reseller's offer of payment

CDW, one of the largest resellers on the planet, will have its data leaked by LockBit after negotiations over the ransom fee broke down, a spokesperson for the cybercrime gang says.…

☐ β˜† βœ‡ The Register - Security

How to stop ransomware thieves WORMing their way into your data

October 6th 2023 at 12:41

Stay immutable in the face of cyber crime adversity, says Object First

Sponsored Feature Most of us dislike cyber criminals, but not many of us dislike them quite as much as Anthony Cusimano.…

☐ β˜† βœ‡ The Register - Security

Google promises Germany to creep on users less after market power probe

October 6th 2023 at 11:56

Regulation complements EU's Digital Markets Act to cover more services

Google has committed to being a little less creepy with user data in response to proceedings from the German Federal Cartel Office (Bundeskartellamt).…

☐ β˜† βœ‡ The Register - Security

GoldDigger Android trojan targets Vietnamese banking apps, code contains hints of wider targets

October 6th 2023 at 01:06

More malware scum using acessibility features to steal personal info

Singapore-based infosec outfit Group-IB on Thursday released details of a new Android trojan that exploits the operating system's accessibility features to steal info that enables theft of personal information.…

☐ β˜† βœ‡ The Register - Security

Cisco warns of critical flaw in Emergency Responder code

October 5th 2023 at 19:45

Hard-coded credentials strike again

Cisco has issued a security advisory about a vulnerability in its Emergency Responder software that would allow an unauthenticated remote attacker to log in to an affected device using the root account.…

☐ β˜† βœ‡ The Register - Security

Another security update, Apple? You're really keeping up with your tech rivals

October 5th 2023 at 18:16

Zero day? More like every day, amirite?

Apple has demonstrated that it can more than hold its own among the tech giants, at least in terms of finding itself on the wrong end of zero-day vulnerabilities.…

☐ β˜† βœ‡ The Register - Security

Lorenz ransomware crew bungles blackmail blueprint by leaking two years of contacts

October 5th 2023 at 10:00

Data leakers become data leakees

The Lorenz ransomware group leaked the details of every person who contacted it via its online contact form over the course of the last two years.…

☐ β˜† βœ‡ The Register - Security

South Korea accuses North of Phish and Ships attack

October 5th 2023 at 05:29

Kim Jong-un looks at industry's progress with green eyes, says South Korea's spy agency

South Korea's National Intelligence Service (NIS) has warned North Korea is attacking its shipbuilding sector.…

☐ β˜† βœ‡ The Register - Security

IT networks under attack via critical Confluence zero-day. Patch now

October 4th 2023 at 22:19

'Handful' of customers hit so far, public-facing instances at risk

Atlassian today said miscreants have exploited a critical bug in on-premises instances of Confluence Server and Confluence Data Center to create and abuse admin accounts within the enterprise colab software.  …

☐ β˜† βœ‡ The Register - Security

Make-me-root 'Looney Tunables' security hole on Linux needs your attention

October 4th 2023 at 21:27

What's up, Doc? Try elevated permissions

Grab security updates for your Linux distributions: there's a security hole that can be fairly easily exploited by rogue users, intruders, and malicious software to gain root access and take over the box.…

☐ β˜† βœ‡ The Register - Security

'Gay furry hackers' brag of second NATO break-in, steal and leak more data

October 4th 2023 at 20:22

'No impact on missions,' military powerhouse insists

NATO is "actively addressing" multiple IT security incidents after a hacktivist group claimed it once again breached some of the military alliance's websites, this time stealing what's claimed to be more than 3,000 files and 9GB of data.…

☐ β˜† βœ‡ The Register - Security

Red Cross lays down hacktivism law as Ukraine war rages on

October 4th 2023 at 19:03

Rules apply to cyber vigilantes and their home nations, but experts cast doubt over potential benefits

New guidelines have been codified to govern the rules of engagement concerning hacktivists involved in ongoing cyber warfare.…

☐ β˜† βœ‡ The Register - Security

CISA barred from coordinating with social media sites to police misinformation

October 4th 2023 at 18:15

The 5th Circuit's re-ruling adds CISA to a list of alleged first-amendment violators. Next stop: Supreme Court

The US Fifth Circuit Court of Appeals has modified a ruling from last month to add the Cybersecurity and Infrastructure Security Agency (CISA) to a list of US government entities prohibited from working with social media outfits to curtail the spread of misinformation. …

☐ β˜† βœ‡ The Register - Security

Trio of TorchServe flaws means PyTorch users need an urgent upgrade

October 4th 2023 at 01:28

Meta, the project's maintainer, shrugs: We fixed it, let's move on

A trio of now-patched security issues in TorchServe, an open-source tool for scaling PyTorch machine-learning models in production, could lead to server takeover and remote code execution (RCE), according to security researchers.…

☐ β˜† βœ‡ The Register - Security

US v Sam Bankman-Fried trial begins ... as imploded crypto-biz boss sues his insurer

October 3rd 2023 at 23:47

After people's funds go up in smoke, ex-CEO seeks cash to foot legal bills

The first of two US government prosecutions of former FTX CEO Sam Bankman-Fried commenced in New York on Monday, only a day after the cryptocurrency tycoon sued his own insurance company for failing to cover his legal costs.…

☐ β˜† βœ‡ The Register - Security

CISA adds latest Chrome zero-day to Known Exploited Vulnerabilities Catalog

October 3rd 2023 at 12:00

Chrome’s second zero-day of the month puts fed security at 'significant risk'

The US's Cybersecurity and Infrastructure Security Agency (CISA) has added the latest actively exploited zero-day vulnerability affecting Google Chrome to its Known Exploited Vulnerabilities (KEV) Catalog.…

☐ β˜† βœ‡ The Register - Security

Co-founder of collapsed crypto biz Three Arrows cuffed at airport

October 3rd 2023 at 01:30

Plus: Philippine state health insurance knocked offline by ransomware, China relaxes data export laws, and more

Asia in brief Zhu Su, co-founder of fallen crypto business Three Arrows Capital (3AC), was arrested last Friday at Changi Airport in Singapore as he attempted to leave the country.…

☐ β˜† βœ‡ The Register - Security

Security researchers believe mass exploitation attempts against WS_FTP have begun

October 2nd 2023 at 13:45

Early signs emerge after Progress Software said there were no active attempts last week

Updated Security researchers have spotted what they believe to be a "possible mass exploitation" of vulnerabilities in Progress Software's WS_FTP Server.…

☐ β˜† βœ‡ The Register - Security

AWS stirs the MadPot – busting bot baddies and eastern espionage

October 2nd 2023 at 10:45

Security exec Mark Ryland spills the tea on hush-hush threat intel tool

Interview AWS has unveiled MadPot, its previously secret threat-intelligence tool that one of the cloud giant's security execs tells us has thwarted Chinese and Russian spies – and millions of bots.…

☐ β˜† βœ‡ The Register - Security

Yes, Singapore immigration plans to scan your face instead of your passport

October 2nd 2023 at 01:00

No, that does not mean you can leave it at home just yet

Last week the internet was abuzz with talk that Singapore's commercial Changi airport was no longer going to require passports for clearance at immigration. Although it is true the paper documentation will be replaced by biometric measures, it's not quite time to pack the document away.…

☐ β˜† βœ‡ The Register - Security

Now MOVEit maker Progress patches holes in WS_FTP

October 1st 2023 at 21:51

Plus: Johnson Controls hit by IT 'incident', Exim and Chrome security updates, and more

Infosec in brief Progress Software, maker of the mass-exploited MOVEit document transfer tool, is back in the news with more must-apply security patches, this time for another file-handling product: WS_FTP.…

☐ β˜† βœ‡ The Register - Security

Microsoft Bing Chat pushes malware via bad ads

September 29th 2023 at 20:54

From AI to just plain aaaiiiee!

Microsoft introduced its Bing Chat AI search assistant in February and a month later began serving ads alongside it to help cover costs.…

☐ β˜† βœ‡ The Register - Security

PhD student guilty of 3D-printing 'kamikaze' drone for Islamic State terrorists

September 29th 2023 at 19:31

'Research purposes' excuse didn't fly

A PhD student has been found guilty of building a potentially deadly drone for Islamic State terrorists, in part using his home 3D printer.…

☐ β˜† βœ‡ The Register - Security

Norway wants Facebook behavioral advertising banned across Europe

September 29th 2023 at 13:45

But Meta was just about to start asking people for their permission!

Norway has told the European Data Protection Board (EDPB) it believes a countrywide ban on Meta harvesting user data to serve up advertising on Facebook and Instagram should be made permanent and extended across Europe.…

☐ β˜† βœ‡ The Register - Security

Chinese snoops stole 60K State Department emails in that Microsoft email heist

September 28th 2023 at 23:13

No classified systems involved apparently, but internal diplomatic notes, travel details, staff SSNs, etc

Chinese snoops stole about 60,000 State Department emails when they broke into Microsoft-hosted Outlook and Exchange Online accounts belonging to US government officials over the summer.…

☐ β˜† βœ‡ The Register - Security

Feds' privacy panel backs renewing Feds' S. 702 spying powers β€”Β but with limits

September 28th 2023 at 21:15

FBI agents ought to get spy court approval before reviewing US persons' chats, board reckons

A privacy panel within the US government today narrowly recommended that Congress reauthorize the Feds' Section 702 spying powers β€” but with some stronger protections for US citizens only.…

☐ β˜† βœ‡ The Register - Security

DARPA takes its long-duration Manta undersea drone for a test-dip

September 28th 2023 at 18:36

Autonomous sub should recharge and resupply in perfect stealth, hopefully

DARPA's extended-duration unmanned undersea vehicle (UUV) is having its first aquatic excursion to test if this naval drone has wings, er, fins.…

☐ β˜† βœ‡ The Register - Security

After failing at privacy, again, Google is working to keep Bard chats out of Search

September 28th 2023 at 07:32

The URLs needed to share chat histories have been indexed. Of course

Google's Bard chatbot is currently being re-educated to better understand privacy.…

☐ β˜† βœ‡ The Register - Security

China's national security minister rates fake news among most pressing cyber threats

September 28th 2023 at 03:58

He's also worried about alliances that freeze out Chinese tech

Chinese minister for national security Chen Yixin has penned an article rating the digital risks his country faces and rated network security incidents as the most realistic source of harm to the Chinternet – both in terms of attacks and the dissemination of fake news.…

☐ β˜† βœ‡ The Register - Security

NYC rights groups say no to grocery store spycams and snooping landlords

September 27th 2023 at 16:30

Letter to City Council supports measures to ban biometric tech from public spaces

"New Yorkers should not be forced to accept biometric surveillance as part of simple activities like buying groceries or taking their kids to a baseball game," more than 30 civil and digital rights organizations said yesterday in a letter backing new privacy laws in the city.…

☐ β˜† βœ‡ The Register - Security

ROBOT crypto attack on RSA is back as Marvin arrives

September 26th 2023 at 17:00

More precise timing tests find many implementations vulnerable

An engineer has identified longstanding undetected flaws in a 25-year-old method for encrypting data using RSA public-key cryptography.…

☐ β˜† βœ‡ The Register - Security

MOVEit breach delivers bundle of 3.4 million baby records

September 26th 2023 at 14:30

Progress Software vulnerability ID'd in enormous burglary at Ontario's BORN

Canada's Better Outcomes Registry & Network (BORN) fears a MOVEit breach allowed cybercriminals to copy 3.4 million people's childcare health records dating back more than a decade.…

☐ β˜† βœ‡ The Register - Security

Ukraine accuses Russian spies of hunting for war-crime info on its servers

September 26th 2023 at 08:00

Russian have shifted tactics in the first half of 2023, with mixed results

The Ukrainian State Service of Special Communications and Information Protection (SSSCIP) has claimed that Russian cyberspies are targeting its servers looking for data about alleged Kremlin-backed war crimes.…

☐ β˜† βœ‡ The Register - Security

Mixin suspends deposits and withdrawals after $200m cryptocurrency heist

September 25th 2023 at 18:34

Cloud provider blamed for loss of 20% of exchange's capital

Mixin Network confirmd on Monday that it has "temporarily suspended" all deposit and withdrawal services after hackers broke into a database and stole about $200 million in funds from the Hong-Kong based cryptocurrency firm. …

☐ β˜† βœ‡ The Register - Security

T-Mobile US exposes some customer data – but don't call it a breach

September 25th 2023 at 02:31

PLUS: Trojan hidden in PoC; cyber insurance surge; pig butchering's new cuts; and the week's critical vulns

Infosec in brief T-Mobile US has had another bad week on the infosec front – this time stemming from a system glitch that exposed customer account data, followed by allegations of another breach the carrier denied.…

☐ β˜† βœ‡ The Register - Security

Apple squashes security bugs after iPhone flaws exploited by Predator spyware

September 22nd 2023 at 19:58

Holes in iOS, macOS and more fixed following tip off from Google, Citizen Lab

Apple emitted patches this week to close security holes that have been exploited in the wild by commercial spyware.…

☐ β˜† βœ‡ The Register - Security

ESA gets the job of building Europe's secure satcomms network

September 22nd 2023 at 05:31

IRIS2 oversight deal signed as constellation’s schedule slips, and Ariane 6 hits another snag

The European Space Agency has signed up to build and launch the European Union's Infrastructure for Resilience, Interconnectivity and Security by Satellite constellation.…

☐ β˜† βœ‡ The Register - Security

US govt IT help desk techie 'leaked top secrets' to foreign nation

September 21st 2023 at 22:10

National defense files can earn you $55K … and espionage charges

A US government worker has been arrested and charged with spying for Ethiopia, according to court documents unsealed Thursday.…

☐ β˜† βœ‡ The Register - Security

TransUnion reckons big dump of stolen customer data came from someone else

September 21st 2023 at 18:58

Prolific info-thief strikes again

Updated Days after a miscreant boasted leaking a 3GB-plus database from TransUnion containing financial information on 58,505 people, the credit-checking agency has claimed the info was actually swiped from a third party.…

☐ β˜† βœ‡ The Register - Security

Cisco spends $28B on data cruncher Splunk in cybersecurity push

September 21st 2023 at 14:55

$157/share cash deal is the largest acquisition in networking titan's history

Cisco is making its most expensive acquisition ever – by far - with an announcement it's buying data crunching software firm Splunk for $157 per share, or approximately $28 billion (Β£22.8b).…

☐ β˜† βœ‡ The Register - Security

Menacing marketeers fined by ICO for 1.9M cold calls

September 21st 2023 at 10:17

Five businesses facing half a million in collective penalties for illegally phoning folk registered with TPS

The UK data watchdog has penalized five businesses it says collectively made 1.9 million cold calls to members of the public, illegally, as those people had opted out of being menaced at home by marketeers.…

☐ β˜† βœ‡ The Register - Security

India's biggest tech centers named as cyber crime hotspots

September 21st 2023 at 06:57

Global tech companies' Bharat offices attract the wrong sort of interest

India is grappling with a three-and-a-half year surge in cyber crime, with analysis suggesting cities like Bengaluru and Gurugram – centers of India's tech development – are hubs of this activity.…

☐ β˜† βœ‡ The Register - Security

Data breach reveals distressing info: People who order pineapple on pizza

September 21st 2023 at 06:27

Pizza Hut Australia says 190,000 customers' info – including order history – has been accessed

Pizza Hut's Australian outpost has suffered a data breach.…

☐ β˜† βœ‡ The Register - Security

Feds raise alarm over Snatch ransomware as extortion crew brags of Veterans Affairs hit

September 20th 2023 at 22:32

Invasion of the data snatchers

The Snatch ransomware crew has listed on its dark-web site the Florida Department of Veterans Affairs as one of its latest victims – as the Feds warn organizations to be on the lookout for indicators of compromise linked to the extortionist gang.…

☐ β˜† βœ‡ The Register - Security

Signal adopts new alphabet jumble to protect chats from quantum computers

September 20th 2023 at 20:28

X3DH readied for retirement as PQXDH is rolled out

Signal has adopted a new key agreement protocol in an effort to keep encrypted Signal chat messages protected from any future quantum computers.…

☐ β˜† βœ‡ The Register - Security

International Criminal Court hit in cyber-attack amid Russia war crimes probe

September 20th 2023 at 19:46

Right as judges issued warrants against Putin

The International Criminal Court said crooks breached its IT systems last week, and that attack isn't over yet, with the ICC saying the "cybersecurity incident" is still ongoing.…

☐ β˜† βœ‡ The Register - Security

Pot calls the kettle hack as China claims Uncle Sam did digital sneak peek first

September 20th 2023 at 17:06

Beijing accuses US of breaking into Huawei servers in 2009

The ongoing face-off between Washington and Beijing over technology and security issues has taken a new twist, with China accusing the US of hacking into the servers of Huawei in 2009 and conducting other cyber-attacks to steal critical data.…

☐ β˜† βœ‡ The Register - Security

Robocall scammers sentenced in US after netting $1.2M via India-based call centers

September 20th 2023 at 13:29

Part of network of crims who used 'trickery and threats' to target elderly

Two Indian nationals have each received 41-month prison sentences in the United States for their involvement in a $1.2 million robocall scam targeting the elderly, according to New Jersey prosecutors on Tuesday.…

☐ β˜† βœ‡ The Register - Security

Sysadmin and spouse admit to part in 'massive' pirated Avaya licenses scam

September 20th 2023 at 12:17

Could spend 20 years in prison after selling $88M in ADI software keys

A sysadmin and his partner pleaded guilty this week to being part of a "massive" international ring that sold software licenses worth $88 million for "significantly below the wholesale price."…

☐ β˜† βœ‡ The Register - Security

Broaden your cyber security knowhow at CyberThreat 2023

September 20th 2023 at 09:23

November’s two day conference sees experts from the cyber security community share their insight and knowledge

Sponsored Post Cyber security remains a top three priority for most, if not all, organisations. The risks associated with failure to implement adequate defences were once again highlighted by the ransomware incident which impacted several hospital computer systems across the US last month.…

☐ β˜† βœ‡ The Register - Security

Singapore may split liability for phishing losses between banks and victims

September 20th 2023 at 05:45

Won't someone please think of the banks?

Singapore officials announced on Monday that next month they will deliver a consultation paper detailing a split liability scheme that will mean both consumers and banks are on the hook for financial losses flowing from scams.…

☐ β˜† βœ‡ The Register - Security

Marvell disputes claim Cavium backdoored chips for Uncle Sam

September 19th 2023 at 20:55

Allegations date back a decade to leaked Snowden docs

Cavium, a maker of semiconductors acquired in 2018 by Marvell, was allegedly identified in documents leaked in 2013 by Edward Snowden as a vendor of semiconductors backdoored for US intelligence. Marvell denies it or Cavium placed backdoors in products at the behest of the US government.…

☐ β˜† βœ‡ The Register - Security

Russian allegedly smuggled US weapons electronics to Moscow

September 19th 2023 at 19:55

Feds claim sniper scope displays sold in sanctions-busting move

A Russian national helped smuggle, via shell companies in Hong Kong, more than $1.6 million in microelectronics to Moscow potentially to support its war against Ukraine, it is claimed.…

☐ β˜† βœ‡ The Register - Security

The Clorox Company admits cyberattack causing 'widescale disruption'

September 19th 2023 at 12:15

Back to 'manual' order processing for $7B household cleaning biz, financial impact will be 'material'

The Clorox Company, makers of bleach and other household cleaning products, doesn't expect operations to return to normal until near month end as it combs over "widescale disruption to operations" caused by cyber baddies.…

☐ β˜† βœ‡ The Register - Security

Australia to build six 'cyber shields' to defend its shores

September 19th 2023 at 03:44

Local corporate regulator warns boards that cyber is totally a directorial duty

Australia will build "six cyber shields around our nation" declared home affairs minister Clare O'Neill yesterday, as part of a national cyber security strategy.…

☐ β˜† βœ‡ The Register - Security

Thousands of Juniper Junos firewalls still open to hijacks, exploit code available to all

September 18th 2023 at 22:30

Unauthenticated and remote code execution possible without dropping a file on disk

About 79 percent of public-facing Juniper SRX firewalls remain vulnerable to a single security flaw can allow an unauthenticated attacker to remotely execute code on the devices, according to threat intelligence platform provider VulnCheck.…

☐ β˜† βœ‡ The Register - Security

Former CIO accuses Penn State of faking cybersecurity compliance

September 18th 2023 at 20:15

Now-NASA boffin not impressed

Last October, Pennsylvania State University (Penn State) was sued by a former chief information officer for allegedly falsifying government security compliance reports.…

☐ β˜† βœ‡ The Register - Security

Microsoft worker accidentally exposes 38TB of sensitive data in GitHub blunder

September 18th 2023 at 18:03

Included secrets, private keys, passwords, 30,000+ internal Teams messages

A Microsoft employee accidentally exposed 38 terabytes of private data while publishing a bucket of open-source AI training data on GitHub, according to Wiz security researchers who spotted the leaky account and reported it to the Windows giant.…

☐ β˜† βœ‡ The Register - Security

California passes bill to set up one-stop data deletion shop

September 18th 2023 at 12:45

Also, LockBit gets a new second stringer, AirTag owners find yet another illicit use, and this week's critical vulns

Infosec in brief Californians may be on their way to the nation's first "do not broker" list with the passage of a bill that would create a one-stop service for residents of the Golden State who want to opt out of being tracked by data brokers. …

❌