FreshRSS

πŸ”’
☐ β˜† βœ‡ The Register - Security

Casio keyed up after data loss hits customers in 149 countries

October 19th 2023 at 19:45

Crooks broke into the ClassPad server and swiped online learning database

Japanese electronics giant Casio said miscreants broke into its ClassPad server and stole a database with personal information belonging to customers in 149 countries.…

☐ β˜† βœ‡ The Register - Security

Europol knocks RagnarLocker offline in second major ransomware bust this year

October 19th 2023 at 16:30

Group will be remembered as staunch negotiator and a bullier of critical infrastructure orgs

Law enforcement agencies have taken over RagnarLocker ransomware group's leak site in an internationally coordinated takedown.…

☐ β˜† βœ‡ The Register - Security

Cybercrim claims fresh 23andMe batch takes leaked records to 5 million

October 19th 2023 at 16:00

Class action lawsuits abound after mega breach

A cybercriminal claims they've uploaded a second batch of stolen profile data from biotech company 23andMe, posting it to the same cybercrime forum that hosted the first batch two weeks ago.…

☐ β˜† βœ‡ The Register - Security

Ex-Navy IT manager gets 5 years in slammer for 2018 database heist

October 19th 2023 at 14:01

Seafaring cybercrim's wife faces similar sentence next month

A former IT manager for the US Navy is facing a five-and-a-half year prison sentence for selling thousands of people's personal records on the dark web.…

☐ β˜† βœ‡ The Register - Security

October Cybersecurity Awareness Month to target internal security risks

October 19th 2023 at 12:35

SANS offers cyber security pros a valuable toolkit of resources to mitigate the potentially serious cybersecurity risks faced by internal staff

Sponsored Post Organisations that fail to adequately address the potential vulnerabilities that internal employees sometimes encounter when developing an IT security strategy are exposing themselves to potentially catastrophic dangers, infosec experts have warned.…

☐ β˜† βœ‡ The Register - Security

D-Link clears up 'exaggerations' around data breach

October 18th 2023 at 14:45

Who knew 3 million actually means 700 in cybercrime forum lingo?

D-Link has confirmed suspicions that it was successfully targeted by cyber criminals, but is talking down the scale of the impact.…

☐ β˜† βœ‡ The Register - Security

CIA exposed to potential intelligence interception due to X's URL bug

October 18th 2023 at 13:00

Musk's mega-app-in-waiting goes from chopping headlines to profile URLs

An ethical hacker has exploited a bug in the way X truncates URLs to take over a CIA Telegram channel used to receive intelligence.…

☐ β˜† βœ‡ The Register - Security

US cybercops urge admins to patch amid ongoing Confluence chaos

October 17th 2023 at 13:02

Do it now, no ifs or buts, says advisory

US authorities have issued an urgent plea to network admins to patch the critical vulnerability in Atlassian Confluence Data Center and Server amid ongoing nation-state exploitation.…

☐ β˜† βœ‡ The Register - Security

British boffins say aircraft could fly on trash, cutting pollution debt by 80%

October 17th 2023 at 07:30

Domestic jets can use 'municipal solid waste' to fly the friendly skies

Sustainable aviation fuels (SAFs) made from sources other than fossil fuels have the potential to reduce emissions by up to 80 percent, UK researchers have found.…

☐ β˜† βœ‡ The Register - Security

Will you meet the directive?

October 17th 2023 at 03:06

Your guide to SEC, DoD 8140.3 and NIS2 changes with the SANS Cyber Compliance Countdown

Sponsored Post Imminent changes to cyber security regulations in the US and Europe demand that public and private sector organizations on both side of the Atlantic keep a close eye on their compliance.…

☐ β˜† βœ‡ The Register - Security

We're not in e-Kansas anymore: State courts reel from 'unauthorized incursion'

October 16th 2023 at 17:32

Fax, post, and human messengers can still be used for filing vital evidence

An unspecified security incident is forcing many state courts across Kansas to rely on paper filings, and it may have continue to do so for weeks, a state judge has warned.…

☐ β˜† βœ‡ The Register - Security

BLOODALCHEMY provides backdoor to southeast Asian nations' secrets

October 16th 2023 at 15:15

Sophisticated malware devs believed to be behind latest addition to toolset of China-aligned attackers

Security researchers have uncovered a backdoor used in attacks against governments and organizations in the Association of Southeast Asian Nations (ASEAN).…

☐ β˜† βœ‡ The Register - Security

Regulator, insurers and customers all coming for Progress after MOVEit breach

October 16th 2023 at 02:58

Also, CISA cataloging new ransomware data points, 17k WP sites hijacked by malware in Sept., and more critical vulns

Infosec in brief The fallout from the exploitation of bugs in Progress Software's MOVEit file transfer software continues, with the US Securities and Exchange Commission (SEC) now investigating the matter, and lots of affected parties seeking compensation. …

☐ β˜† βœ‡ The Register - Security

530K people's info feared stolen from cloud PC gaming biz Shadow

October 13th 2023 at 18:57

Will players press start to continue with this outfit?

Shadow, which hosts Windows PC gaming in the cloud among other services, has confirmed criminals stole a database containing customer data following a social-engineering attack against one of its employees.…

☐ β˜† βœ‡ The Register - Security

Thwarted ransomware raid targeting WS_FTP servers demanded just 0.018 BTC

October 13th 2023 at 18:15

Early attempt to exploit latest Progress Software bug spotted in the wild

An early ransomware campaign against organizations by exploiting the vulnerability in Progress Software's WS_FTP Server was this week spotted by security researchers.…

☐ β˜† βœ‡ The Register - Security

Calls for Visual Studio security tweak fall on deaf ears despite one-click RCE exploit

October 13th 2023 at 15:28

Two years on and Microsoft refuses to address the issue

Perceived weaknesses in the security of Microsoft's Visual Studio IDE are being raised once again this week with a fresh single-click exploit.…

☐ β˜† βœ‡ The Register - Security

Squid games: 35 security holes still unpatched in proxy after 2 years, now public

October 13th 2023 at 00:21

We'd like to say don't panic … but maybe?

35 vulnerabilities in the Squid caching proxy remain unfixed more than two years after being found and disclosed to the open source project's maintainers, according to the person who reported them.…

☐ β˜† βœ‡ The Register - Security

Everest cybercriminals offer corporate insiders cold, hard cash for remote access

October 12th 2023 at 12:42

The ransomware gang changes identities more than Jason Bourne

The Everest ransomware group is stepping up its efforts to purchase access to corporate networks directly from employees amid what researchers believe to be a major transition for the cybercriminals.…

☐ β˜† βœ‡ The Register - Security

Building cyber resilience with data vaults

October 12th 2023 at 12:29

How continuous data protection and isolated cyber recovery vaults provide effective defense against ransomware

Sponsored Feature In August 2023, Danish hosting subsidiaries CloudNordic and AzeroCloud were on the receiving end of one of the most serious ransomware attacks ever made public by a cloud services company.…

☐ β˜† βœ‡ The Register - Security

US construction giant unearths concrete evidence of cyberattack

October 12th 2023 at 10:55

Simpson Manufacturing yanks systems offline, warns of ongoing disruption

Simpson Manufacturing Company yanked some tech systems offline this week to contain a cyberattack it expects will "continue to cause disruption."…

☐ β˜† βœ‡ The Register - Security

HM Government has partnered with SANS to train cyber security experts

October 12th 2023 at 08:42

Partner Content According to the Cyber Security Breaches Survey 26 percent of medium businesses, 37 percent of large businesses and 25 percent of high-income charities have experienced cyber crime in the last 12 months.…

☐ β˜† βœ‡ The Register - Security

US Navy sailor admits selling secret military blueprints to China for $15K

October 11th 2023 at 19:42

Worth it for 20 years behind bars?

A US Navy service member pleaded guilty yesterday to receiving thousands of dollars in bribes from a Chinese spymaster in exchange for passing on American military secrets.…

☐ β˜† βœ‡ The Register - Security

curl vulnerabilities ironed out with patches after week-long tease

October 11th 2023 at 10:05

The coordinated disclosure didn’t quite go to plan, though

Updated After a week of rampant speculation about the nature of the security issues in curl, the latest version of the command line transfer tool was finally released today.…

☐ β˜† βœ‡ The Register - Security

What to expect when the UK-US Data Bridge comes into force this week

October 11th 2023 at 09:15

Britain's privacy watchdog still not happy that agreement 'appropriately' protects sensitive data

Opinion The UK Extension to the EU-US Data Privacy Framework (aka Data Bridge) will enter into force on October 12, allowing certifying entities to easily transfer personal data from the UK to the US.…

☐ β˜† βœ‡ The Register - Security

It's 2023 and Microsoft WordPad can be exploited to hijack vulnerable systems

October 10th 2023 at 23:49

Happy Halloween! Security bugs under attack squashed, more flaws fixed

Patch Tuesday Microsoft on Tuesday issued more than 100 security updates to fix flaws in its products, including two bugs that are already under active attack, as well as addressing an HTTP/2 weakness that has also been exploited in the wild.…

☐ β˜† βœ‡ The Register - Security

SBF on trial: The Python code that allegedly let Alameda hedge fund spend people's FTX deposits

October 10th 2023 at 21:21

And Caroline Ellison says she was told by Bankman-Fried to take $10B from customer accounts

At the fraud trial of former FTX head Sam Bankman-Fried, prosecutors presented the jury with Python code for the FTX backend that allowed flagged client accounts to spend money they didn't have on the cryptocurrency exchange.…

☐ β˜† βœ‡ The Register - Security

HTTP/2 'Rapid Reset' zero-day exploited in biggest DDoS deluge seen yet

October 10th 2023 at 20:37

Botnet storm drowned last record with 398 million requests per second

A zero-day vulnerability in the HTTP/2 protocol was exploited to launch the largest distributed denial-of-service (DDoS) attack on record, according to Cloudflare.…

☐ β˜† βœ‡ The Register - Security

Mirai reloads exploit arsenal as botnet embarks on another expansion drive

October 10th 2023 at 18:15

With 13 new payloads it's the biggest update to the botnet in months

The infamous Mirai botnet was spotted by researchers who say it is spinning up again, this time with an "aggressively updated arsenal of exploits."…

☐ β˜† βœ‡ The Register - Security

Researcher bags two-for-one deal on Linux bugs while probing GNOME component

October 10th 2023 at 16:01

One-click exploit could potentially affect most major distros

Researchers discovered a high-severity remote code execution (RCE) vulnerability in an inherent component of GNOME-based Linux distros, potentially impacting a huge number of users.…

☐ β˜† βœ‡ The Register - Security

Fresh curl tomorrow will patch 'worst' security flaw in ages

October 10th 2023 at 14:30

It’s bad, folks. Pair of CVEs incoming on October 11

Updated Start your patch engines – a new version of curl is due tomorrow that addresses a pair of flaws, one of which lead developer Daniel Stenberg describes as "probably the worst curl security flaw in a long time."…

☐ β˜† βœ‡ The Register - Security

Ransomware attacks register record speeds thanks to success of infosec industry

October 10th 2023 at 08:30

Dwell times drop to hours rather than days for the first time

The time taken by cyber attackers between gaining an initial foothold in a victim's environment and deploying ransomware has fallen to 24 hours, according to a study.…

☐ β˜† βœ‡ The Register - Security

Exercise Cyber Star tests Singapore response

October 10th 2023 at 02:31

How SANS is helping boost the island’s defenses against whole-of-nation cyber attacks

Sponsored The cyber attack which culminated in the personal details of 1.5m patients being compromised after hackers broke into the databases of SingHealth in 2018 provides a stark illustration of why organizations in Singapore need to remain vigilant and well protected against further incidents.…

☐ β˜† βœ‡ The Register - Security

DoJ: Ex-soldier tried to pass secrets to China after seeking a 'subreddit about spy stuff'

October 9th 2023 at 15:15

FBI agent claims sergeant with top clearance offered access to DoD tech systems

A former US Army Sergeant with Top Secret US military clearance created a Word document entitled "Important Information to Share with Chinese Government," according to an FBI agent's sworn declaration.…

☐ β˜† βœ‡ The Register - Security

Hacktivist attacks erupt in Middle East following Hamas assault on Israel

October 9th 2023 at 13:00

Groups range from known collectives to new outfits eager to raise their profile

Hacktivism efforts have proliferated rapidly in the Middle East following the official announcement of a war between Palestine and Israel.…

☐ β˜† βœ‡ The Register - Security

Datacenter cabling biz Volex confirms digital break-in

October 9th 2023 at 11:30

All sites operational, no 'material' financial impact expected but stock markets still worried

Volex, the British integrated maker of critical power and data transmission cables, confirmed this morning that intruders accessed data after breaking into its tech infrastructure.…

☐ β˜† βœ‡ The Register - Security

Chinese smart TV boxes infected with malware in PEACHPIT ad fraud campaign

October 9th 2023 at 01:27

PLUS: Sony admits to MoveITbreach; Blackbaud fined again, Qakbot's sorta back from the dead; and more

Infosec in brief Bot defense software vendor Human Security last week detailed an attack that "sold off-brand mobile and Connected TV (CTV) devices on popular online retailers and resale sites … preloaded with a known malware called Triada."…

☐ β˜† βœ‡ The Register - Security

CISA reveals 'Admin123' as top security threat in cyber sloppiness chart

October 6th 2023 at 18:42

Calls for wider adoption of security-by-design principles continue to ring loudly from Uncle Sam

The US Cybersecurity and Infrastructure Security Agency (CISA) and the National Security Agency (NSA) are blaming unchanged default credentials as the prime security misconfiguration that leads to cyberattacks.…

☐ β˜† βœ‡ The Register - Security

MGM Resorts attackers hit personal data jackpot, but house lost $100M

October 6th 2023 at 15:30

Racecars and cyber insurance will balance its books in no time, though

MGM Resorts has admitted that the cyberattack it suffered in September will likely cost the company at least $100 million.…

☐ β˜† βœ‡ The Register - Security

CDW data to be leaked next week after negotiations with LockBit break down

October 6th 2023 at 13:21

Ransomware spokesperson scoffs at IT reseller's offer of payment

CDW, one of the largest resellers on the planet, will have its data leaked by LockBit after negotiations over the ransom fee broke down, a spokesperson for the cybercrime gang says.…

☐ β˜† βœ‡ The Register - Security

How to stop ransomware thieves WORMing their way into your data

October 6th 2023 at 12:41

Stay immutable in the face of cyber crime adversity, says Object First

Sponsored Feature Most of us dislike cyber criminals, but not many of us dislike them quite as much as Anthony Cusimano.…

☐ β˜† βœ‡ The Register - Security

Google promises Germany to creep on users less after market power probe

October 6th 2023 at 11:56

Regulation complements EU's Digital Markets Act to cover more services

Google has committed to being a little less creepy with user data in response to proceedings from the German Federal Cartel Office (Bundeskartellamt).…

☐ β˜† βœ‡ The Register - Security

GoldDigger Android trojan targets Vietnamese banking apps, code contains hints of wider targets

October 6th 2023 at 01:06

More malware scum using acessibility features to steal personal info

Singapore-based infosec outfit Group-IB on Thursday released details of a new Android trojan that exploits the operating system's accessibility features to steal info that enables theft of personal information.…

☐ β˜† βœ‡ The Register - Security

Cisco warns of critical flaw in Emergency Responder code

October 5th 2023 at 19:45

Hard-coded credentials strike again

Cisco has issued a security advisory about a vulnerability in its Emergency Responder software that would allow an unauthenticated remote attacker to log in to an affected device using the root account.…

☐ β˜† βœ‡ The Register - Security

Another security update, Apple? You're really keeping up with your tech rivals

October 5th 2023 at 18:16

Zero day? More like every day, amirite?

Apple has demonstrated that it can more than hold its own among the tech giants, at least in terms of finding itself on the wrong end of zero-day vulnerabilities.…

☐ β˜† βœ‡ The Register - Security

Lorenz ransomware crew bungles blackmail blueprint by leaking two years of contacts

October 5th 2023 at 10:00

Data leakers become data leakees

The Lorenz ransomware group leaked the details of every person who contacted it via its online contact form over the course of the last two years.…

☐ β˜† βœ‡ The Register - Security

South Korea accuses North of Phish and Ships attack

October 5th 2023 at 05:29

Kim Jong-un looks at industry's progress with green eyes, says South Korea's spy agency

South Korea's National Intelligence Service (NIS) has warned North Korea is attacking its shipbuilding sector.…

☐ β˜† βœ‡ The Register - Security

IT networks under attack via critical Confluence zero-day. Patch now

October 4th 2023 at 22:19

'Handful' of customers hit so far, public-facing instances at risk

Atlassian today said miscreants have exploited a critical bug in on-premises instances of Confluence Server and Confluence Data Center to create and abuse admin accounts within the enterprise colab software.  …

☐ β˜† βœ‡ The Register - Security

Make-me-root 'Looney Tunables' security hole on Linux needs your attention

October 4th 2023 at 21:27

What's up, Doc? Try elevated permissions

Grab security updates for your Linux distributions: there's a security hole that can be fairly easily exploited by rogue users, intruders, and malicious software to gain root access and take over the box.…

☐ β˜† βœ‡ The Register - Security

'Gay furry hackers' brag of second NATO break-in, steal and leak more data

October 4th 2023 at 20:22

'No impact on missions,' military powerhouse insists

NATO is "actively addressing" multiple IT security incidents after a hacktivist group claimed it once again breached some of the military alliance's websites, this time stealing what's claimed to be more than 3,000 files and 9GB of data.…

☐ β˜† βœ‡ The Register - Security

Red Cross lays down hacktivism law as Ukraine war rages on

October 4th 2023 at 19:03

Rules apply to cyber vigilantes and their home nations, but experts cast doubt over potential benefits

New guidelines have been codified to govern the rules of engagement concerning hacktivists involved in ongoing cyber warfare.…

☐ β˜† βœ‡ The Register - Security

CISA barred from coordinating with social media sites to police misinformation

October 4th 2023 at 18:15

The 5th Circuit's re-ruling adds CISA to a list of alleged first-amendment violators. Next stop: Supreme Court

The US Fifth Circuit Court of Appeals has modified a ruling from last month to add the Cybersecurity and Infrastructure Security Agency (CISA) to a list of US government entities prohibited from working with social media outfits to curtail the spread of misinformation. …

☐ β˜† βœ‡ The Register - Security

Trio of TorchServe flaws means PyTorch users need an urgent upgrade

October 4th 2023 at 01:28

Meta, the project's maintainer, shrugs: We fixed it, let's move on

A trio of now-patched security issues in TorchServe, an open-source tool for scaling PyTorch machine-learning models in production, could lead to server takeover and remote code execution (RCE), according to security researchers.…

☐ β˜† βœ‡ The Register - Security

US v Sam Bankman-Fried trial begins ... as imploded crypto-biz boss sues his insurer

October 3rd 2023 at 23:47

After people's funds go up in smoke, ex-CEO seeks cash to foot legal bills

The first of two US government prosecutions of former FTX CEO Sam Bankman-Fried commenced in New York on Monday, only a day after the cryptocurrency tycoon sued his own insurance company for failing to cover his legal costs.…

☐ β˜† βœ‡ The Register - Security

CISA adds latest Chrome zero-day to Known Exploited Vulnerabilities Catalog

October 3rd 2023 at 12:00

Chrome’s second zero-day of the month puts fed security at 'significant risk'

The US's Cybersecurity and Infrastructure Security Agency (CISA) has added the latest actively exploited zero-day vulnerability affecting Google Chrome to its Known Exploited Vulnerabilities (KEV) Catalog.…

☐ β˜† βœ‡ The Register - Security

Co-founder of collapsed crypto biz Three Arrows cuffed at airport

October 3rd 2023 at 01:30

Plus: Philippine state health insurance knocked offline by ransomware, China relaxes data export laws, and more

Asia in brief Zhu Su, co-founder of fallen crypto business Three Arrows Capital (3AC), was arrested last Friday at Changi Airport in Singapore as he attempted to leave the country.…

☐ β˜† βœ‡ The Register - Security

Security researchers believe mass exploitation attempts against WS_FTP have begun

October 2nd 2023 at 13:45

Early signs emerge after Progress Software said there were no active attempts last week

Updated Security researchers have spotted what they believe to be a "possible mass exploitation" of vulnerabilities in Progress Software's WS_FTP Server.…

☐ β˜† βœ‡ The Register - Security

AWS stirs the MadPot – busting bot baddies and eastern espionage

October 2nd 2023 at 10:45

Security exec Mark Ryland spills the tea on hush-hush threat intel tool

Interview AWS has unveiled MadPot, its previously secret threat-intelligence tool that one of the cloud giant's security execs tells us has thwarted Chinese and Russian spies – and millions of bots.…

☐ β˜† βœ‡ The Register - Security

Yes, Singapore immigration plans to scan your face instead of your passport

October 2nd 2023 at 01:00

No, that does not mean you can leave it at home just yet

Last week the internet was abuzz with talk that Singapore's commercial Changi airport was no longer going to require passports for clearance at immigration. Although it is true the paper documentation will be replaced by biometric measures, it's not quite time to pack the document away.…

☐ β˜† βœ‡ The Register - Security

Now MOVEit maker Progress patches holes in WS_FTP

October 1st 2023 at 21:51

Plus: Johnson Controls hit by IT 'incident', Exim and Chrome security updates, and more

Infosec in brief Progress Software, maker of the mass-exploited MOVEit document transfer tool, is back in the news with more must-apply security patches, this time for another file-handling product: WS_FTP.…

☐ β˜† βœ‡ The Register - Security

Microsoft Bing Chat pushes malware via bad ads

September 29th 2023 at 20:54

From AI to just plain aaaiiiee!

Microsoft introduced its Bing Chat AI search assistant in February and a month later began serving ads alongside it to help cover costs.…

❌