FreshRSS

πŸ”’
☐ β˜† βœ‡ The Register - Security

LockBit alleges it boarded Boeing, stole 'sensitive data'

October 30th 2023 at 02:30

ALSO: CISA begs for a consistent budget, Las Vegas school breach; Nigeria arrests six cyber princes, the week's critical vulnerabilities

Security In Brief Notorious ransomware gang LockBit has reportedly exfiltrated β€œa tremendous amount of sensitive data from aerospace outfit Boeing.…

☐ β˜† βœ‡ The Register - Security

Apple Private Wi-Fi hasn't worked for the past three years

October 27th 2023 at 22:30

Not exactly the MAC daddy

Three years after Apple introduced a menu setting called Private Wi-Fi Address, a way to spoof network identifiers called MAC addresses, the privacy protection may finally work as advertised, thanks to a software fix.…

☐ β˜† βœ‡ The Register - Security

F5 hurriedly squashes BIG-IP remote code execution bug

October 27th 2023 at 17:34

Fixes came earlier than scheduled as vulnerability became known to outsiders

F5 has issued a fix for a remote code execution (RCE) bug in its BIG-IP suite carrying a near-maximum severity score.…

☐ β˜† βœ‡ The Register - Security

Microsoft unveils shady shenanigans of Octo Tempest and their cyber-trickery toolkit

October 27th 2023 at 12:43

Gang thought to be behind attack on MGM Resorts has a skillset larger than most cybercrime groups in existence

Microsoft's latest report on "one of the most dangerous financial criminal groups" operating offers security pros an abundance of threat intelligence to protect themselves from its myriad tactics.…

☐ β˜† βœ‡ The Register - Security

King Charles III signs off on UK Online Safety Act, with unenforceable spying clause

October 27th 2023 at 09:51

It's now up to Ofcom to sort out this messy legislation

With the assent of King Charles, the United Kingdom's Online Safety Act has become law, one that the British government says will "make the UK the safest place in the world to be online."…

☐ β˜† βœ‡ The Register - Security

Apple drops urgent patch against obtuse TriangleDB iPhone malware

October 26th 2023 at 21:15

Kaspersky first found this software nasty on its own phones

Apple pushed several security fixes on Wednesday, including one for all iPhone and iPads used before September last year that has already been exploited by cyber snoops.…

☐ β˜† βœ‡ The Register - Security

Forget the outside hacker, the bigger threat is inside by the coffee machine

October 26th 2023 at 20:15

After a week of incidents, Register vultures pick over the innards

Kettle In this week's Kettle the topic is one that's been much in the news this week - the much-underrated insider threat issue.…

☐ β˜† βœ‡ The Register - Security

Side channel attacks take bite out of Apple silicon with iLeakage exploit

October 26th 2023 at 17:45

Nearly six years on from Spectre and Meltdown, novel method steals passwords, emails, texts

University researchers have developed a novel exploit that can steal information from virtually all modern Apple Macs, iPhones, and iPads.…

☐ β˜† βœ‡ The Register - Security

ServiceNow quietly addresses unauthenticated data exposure flaw from 2015

October 26th 2023 at 08:30

Researcher who publicized issue brands company’s communication 'appalling'

ServiceNow is issuing a fix for a flaw that exposes data after a researcher published a method for unauthenticated attackers to steal an organization's sensitive files.…

☐ β˜† βœ‡ The Register - Security

Canada goosed as attackers shutter hospitals and China deepfakes its politicians

October 25th 2023 at 19:45

Eh? Canucks cracked by cyber crims

Cybercriminals have Canada in the crosshairs, with five Ontario hospitals and a fresh Spamoflague disinformation campaign targeting "dozens" of Canadian government officials, including the PM.…

☐ β˜† βœ‡ The Register - Security

Pro-Russia group exploits Roundcube zero-day in attacks on European government emails

October 25th 2023 at 16:45

With this zero-day, researchers say the 'scrappy' group is stepping up its operations

The Winter Vivern cyber spy group is exploiting an XSS zero-day vulnerability in attacks on European governments.…

☐ β˜† βœ‡ The Register - Security

A fortified data vault to give you peace of mind

October 25th 2023 at 12:53

Watch our webinar to hear more about comprehensive data protection from Zerto and HPE

Webinar It's a challenge to maintain the availability and security of mission critical data in today's environment. As IT teams know only too well, there's no quiet season for enterprise IT operations or cyber threats.…

☐ β˜† βœ‡ The Register - Security

Hunters International leaks pre-op plastic surgery pics in negotiation no-no

October 25th 2023 at 08:30

No honor among thieves as group denies Hive ransomware links

A newly emerged ransomware gang claims to have successfully gained access to the systems of a US plastic surgeon's clinic, leaking patients' pre-operation pictures in an attempt to hurry a ransom payment.…

☐ β˜† βœ‡ The Register - Security

VMware reveals critical vCenter vuln that you may have patched already without knowing it

October 25th 2023 at 04:30

Takes rare step of issuing patches for end-of-life versions, as some staff report end-of-career letters

VMware has disclosed a critical vulnerability in its vCenter Server – and that it issued an update to fix it weeks ago, along with patches for unsupported versions of the software.…

☐ β˜† βœ‡ The Register - Security

Hot fuzz: Cascade finds dozens of RISC-V chip bugs using random data storm

October 24th 2023 at 21:41

ETH Zurich boffins say they've devised a better CPU fuzzer to find flaws

Video Boffins from ETH Zurich have devised a novel fuzzer for finding bugs in RISC-V chips and have used it to find more than three dozen.…

☐ β˜† βœ‡ The Register - Security

Citrix urges 'immediate; patch for critical NetScaler bug as exploit POC made public

October 24th 2023 at 21:00

At this point, just assume your kit is compromised

Citrix has urged admins to "immediately" apply a fix for CVE-2023-4966, a critical information disclosure bug that affects NetScaler ADC and NetScaler Gateway, admitting it has been exploited.…

☐ β˜† βœ‡ The Register - Security

Ex-NSA techie pleads guilty to selling state secrets to Russia

October 24th 2023 at 16:45

Wannabe spy undone by system logs, among other lapses in judgement

A former US National Security Agency techie has plead guilty to six counts of violating the Espionage Act after being caught handing classified information to FBI agents he thought were Russian spies. …

☐ β˜† βœ‡ The Register - Security

1Password confirms attacker tried to pull list of admin users after Okta intrusion

October 24th 2023 at 15:15

Says logins are safe, as high-profile customers complain they knew about the breach before Okta

1Password is confirming it was attacked by cyber criminals after Okta was breached for the second time in as many years, but says customers' login details are safe.…

☐ β˜† βœ‡ The Register - Security

Element users are asking for protection against government encryption busting

October 24th 2023 at 14:30

NATO, United Nations, US DoD, and French government among its customer base

Element, one of the companies behind decentralized comms platform Matrix, says customers are asking it to insert a protective clause from the encryption-busting element of UK government's Online Safety Bill (OSB).…

☐ β˜† βœ‡ The Register - Security

Irish cops data debacle exposes half a million motorist records

October 24th 2023 at 10:02

Details of civilians and Garda officers were included, as well as high-res scans of identity documents

A third-party contractor running a database without password protection exposed more than 500,000 records related to vehicle seizures by the Irish National Police (An Garda SΓ­ochΓ‘na, "Garda").…

☐ β˜† βœ‡ The Register - Security

Helping you bridge the cloud security gap

October 24th 2023 at 08:15

Learn how to implement effective identity and access management with Entra ID and SANS

Sponsored Post The job of the cyber security professional is never easy, and it gets progressively harder with the movement of sensitive data and applications across the multiple different on and off premise systems that make up modern hybrid cloud environments.…

☐ β˜† βœ‡ The Register - Security

Scammers use India’s real-time payment system to siphon off money, send it to China

October 24th 2023 at 03:30

Countries signed on for India’s stack might watch out

China-based scammers are using a combination of fake loan apps and India's real-time mobile payment system, Unified Payments Interface (UPI), to separate victims from their cash, according to a report by threat intel firm CloudSEK.…

☐ β˜† βœ‡ The Register - Security

Cisco fixes critical IOS XE bug but malware crew way ahead of them

October 23rd 2023 at 22:15

Initial fall in infected devices indicates evolution, not extinction, of attack code

After a six-day wait, Cisco started rolling out a patch for a critical bug that miscreants had exploited to install implants in thousands of devices. Alas, it seems, the security results have been mixed since the attackers got wise.…

☐ β˜† βœ‡ The Register - Security

DC elections agency warns entire voting roll may have been stolen

October 23rd 2023 at 19:15

Home of the Republic seemingly hit by Sony/NTT Docomo ransomware crew

The US Capital's election agency says a ransomware crew might have stolen its entire voter roll, which includes the personal information of all registered voters in the District of Columbia.…

☐ β˜† βœ‡ The Register - Security

Microsoft opens early access to AI assistant for infosec, Security Copilot

October 23rd 2023 at 13:00

Copilotization of all things continues... as helper offers incident reports to share with the boss and more

Microsoft is opening up the early access program for its flagship cybersecurity AI product, which marks the inevitable folding in of Copilot into its infosec suite.…

☐ β˜† βœ‡ The Register - Security

Redefining united data protection

October 23rd 2023 at 12:52

Where adopting a resilient and integrated approach to backup and disaster recovery makes sense

Webinar There is no longer an off button for businesses and organizations, no closed signs, or downtime. This means enterprise IT operations and data assets must be protected round the clock in all operating environments.…

☐ β˜† βœ‡ The Register - Security

Admin behind E-Root stolen creds souk extradited to US

October 20th 2023 at 19:45

There was a young man from Moldova, who the Feds just want to roll over, but with 20 inside, and nowhere to hide, he just wants it all to be over

A Moldovan who allegedly ran the compromised-credential marketplace E-Root has been extradited from the UK to America to stand trial.…

☐ β˜† βœ‡ The Register - Security

Casio keyed up after data loss hits customers in 149 countries

October 19th 2023 at 19:45

Crooks broke into the ClassPad server and swiped online learning database

Japanese electronics giant Casio said miscreants broke into its ClassPad server and stole a database with personal information belonging to customers in 149 countries.…

☐ β˜† βœ‡ The Register - Security

Europol knocks RagnarLocker offline in second major ransomware bust this year

October 19th 2023 at 16:30

Group will be remembered as staunch negotiator and a bullier of critical infrastructure orgs

Law enforcement agencies have taken over RagnarLocker ransomware group's leak site in an internationally coordinated takedown.…

☐ β˜† βœ‡ The Register - Security

Cybercrim claims fresh 23andMe batch takes leaked records to 5 million

October 19th 2023 at 16:00

Class action lawsuits abound after mega breach

A cybercriminal claims they've uploaded a second batch of stolen profile data from biotech company 23andMe, posting it to the same cybercrime forum that hosted the first batch two weeks ago.…

☐ β˜† βœ‡ The Register - Security

Ex-Navy IT manager gets 5 years in slammer for 2018 database heist

October 19th 2023 at 14:01

Seafaring cybercrim's wife faces similar sentence next month

A former IT manager for the US Navy is facing a five-and-a-half year prison sentence for selling thousands of people's personal records on the dark web.…

☐ β˜† βœ‡ The Register - Security

October Cybersecurity Awareness Month to target internal security risks

October 19th 2023 at 12:35

SANS offers cyber security pros a valuable toolkit of resources to mitigate the potentially serious cybersecurity risks faced by internal staff

Sponsored Post Organisations that fail to adequately address the potential vulnerabilities that internal employees sometimes encounter when developing an IT security strategy are exposing themselves to potentially catastrophic dangers, infosec experts have warned.…

☐ β˜† βœ‡ The Register - Security

D-Link clears up 'exaggerations' around data breach

October 18th 2023 at 14:45

Who knew 3 million actually means 700 in cybercrime forum lingo?

D-Link has confirmed suspicions that it was successfully targeted by cyber criminals, but is talking down the scale of the impact.…

☐ β˜† βœ‡ The Register - Security

CIA exposed to potential intelligence interception due to X's URL bug

October 18th 2023 at 13:00

Musk's mega-app-in-waiting goes from chopping headlines to profile URLs

An ethical hacker has exploited a bug in the way X truncates URLs to take over a CIA Telegram channel used to receive intelligence.…

☐ β˜† βœ‡ The Register - Security

US cybercops urge admins to patch amid ongoing Confluence chaos

October 17th 2023 at 13:02

Do it now, no ifs or buts, says advisory

US authorities have issued an urgent plea to network admins to patch the critical vulnerability in Atlassian Confluence Data Center and Server amid ongoing nation-state exploitation.…

☐ β˜† βœ‡ The Register - Security

British boffins say aircraft could fly on trash, cutting pollution debt by 80%

October 17th 2023 at 07:30

Domestic jets can use 'municipal solid waste' to fly the friendly skies

Sustainable aviation fuels (SAFs) made from sources other than fossil fuels have the potential to reduce emissions by up to 80 percent, UK researchers have found.…

☐ β˜† βœ‡ The Register - Security

Will you meet the directive?

October 17th 2023 at 03:06

Your guide to SEC, DoD 8140.3 and NIS2 changes with the SANS Cyber Compliance Countdown

Sponsored Post Imminent changes to cyber security regulations in the US and Europe demand that public and private sector organizations on both side of the Atlantic keep a close eye on their compliance.…

☐ β˜† βœ‡ The Register - Security

We're not in e-Kansas anymore: State courts reel from 'unauthorized incursion'

October 16th 2023 at 17:32

Fax, post, and human messengers can still be used for filing vital evidence

An unspecified security incident is forcing many state courts across Kansas to rely on paper filings, and it may have continue to do so for weeks, a state judge has warned.…

☐ β˜† βœ‡ The Register - Security

BLOODALCHEMY provides backdoor to southeast Asian nations' secrets

October 16th 2023 at 15:15

Sophisticated malware devs believed to be behind latest addition to toolset of China-aligned attackers

Security researchers have uncovered a backdoor used in attacks against governments and organizations in the Association of Southeast Asian Nations (ASEAN).…

☐ β˜† βœ‡ The Register - Security

Regulator, insurers and customers all coming for Progress after MOVEit breach

October 16th 2023 at 02:58

Also, CISA cataloging new ransomware data points, 17k WP sites hijacked by malware in Sept., and more critical vulns

Infosec in brief The fallout from the exploitation of bugs in Progress Software's MOVEit file transfer software continues, with the US Securities and Exchange Commission (SEC) now investigating the matter, and lots of affected parties seeking compensation. …

☐ β˜† βœ‡ The Register - Security

530K people's info feared stolen from cloud PC gaming biz Shadow

October 13th 2023 at 18:57

Will players press start to continue with this outfit?

Shadow, which hosts Windows PC gaming in the cloud among other services, has confirmed criminals stole a database containing customer data following a social-engineering attack against one of its employees.…

☐ β˜† βœ‡ The Register - Security

Thwarted ransomware raid targeting WS_FTP servers demanded just 0.018 BTC

October 13th 2023 at 18:15

Early attempt to exploit latest Progress Software bug spotted in the wild

An early ransomware campaign against organizations by exploiting the vulnerability in Progress Software's WS_FTP Server was this week spotted by security researchers.…

☐ β˜† βœ‡ The Register - Security

Calls for Visual Studio security tweak fall on deaf ears despite one-click RCE exploit

October 13th 2023 at 15:28

Two years on and Microsoft refuses to address the issue

Perceived weaknesses in the security of Microsoft's Visual Studio IDE are being raised once again this week with a fresh single-click exploit.…

☐ β˜† βœ‡ The Register - Security

Squid games: 35 security holes still unpatched in proxy after 2 years, now public

October 13th 2023 at 00:21

We'd like to say don't panic … but maybe?

35 vulnerabilities in the Squid caching proxy remain unfixed more than two years after being found and disclosed to the open source project's maintainers, according to the person who reported them.…

☐ β˜† βœ‡ The Register - Security

Everest cybercriminals offer corporate insiders cold, hard cash for remote access

October 12th 2023 at 12:42

The ransomware gang changes identities more than Jason Bourne

The Everest ransomware group is stepping up its efforts to purchase access to corporate networks directly from employees amid what researchers believe to be a major transition for the cybercriminals.…

☐ β˜† βœ‡ The Register - Security

Building cyber resilience with data vaults

October 12th 2023 at 12:29

How continuous data protection and isolated cyber recovery vaults provide effective defense against ransomware

Sponsored Feature In August 2023, Danish hosting subsidiaries CloudNordic and AzeroCloud were on the receiving end of one of the most serious ransomware attacks ever made public by a cloud services company.…

☐ β˜† βœ‡ The Register - Security

US construction giant unearths concrete evidence of cyberattack

October 12th 2023 at 10:55

Simpson Manufacturing yanks systems offline, warns of ongoing disruption

Simpson Manufacturing Company yanked some tech systems offline this week to contain a cyberattack it expects will "continue to cause disruption."…

☐ β˜† βœ‡ The Register - Security

HM Government has partnered with SANS to train cyber security experts

October 12th 2023 at 08:42

Partner Content According to the Cyber Security Breaches Survey 26 percent of medium businesses, 37 percent of large businesses and 25 percent of high-income charities have experienced cyber crime in the last 12 months.…

☐ β˜† βœ‡ The Register - Security

US Navy sailor admits selling secret military blueprints to China for $15K

October 11th 2023 at 19:42

Worth it for 20 years behind bars?

A US Navy service member pleaded guilty yesterday to receiving thousands of dollars in bribes from a Chinese spymaster in exchange for passing on American military secrets.…

☐ β˜† βœ‡ The Register - Security

curl vulnerabilities ironed out with patches after week-long tease

October 11th 2023 at 10:05

The coordinated disclosure didn’t quite go to plan, though

Updated After a week of rampant speculation about the nature of the security issues in curl, the latest version of the command line transfer tool was finally released today.…

☐ β˜† βœ‡ The Register - Security

What to expect when the UK-US Data Bridge comes into force this week

October 11th 2023 at 09:15

Britain's privacy watchdog still not happy that agreement 'appropriately' protects sensitive data

Opinion The UK Extension to the EU-US Data Privacy Framework (aka Data Bridge) will enter into force on October 12, allowing certifying entities to easily transfer personal data from the UK to the US.…

☐ β˜† βœ‡ The Register - Security

It's 2023 and Microsoft WordPad can be exploited to hijack vulnerable systems

October 10th 2023 at 23:49

Happy Halloween! Security bugs under attack squashed, more flaws fixed

Patch Tuesday Microsoft on Tuesday issued more than 100 security updates to fix flaws in its products, including two bugs that are already under active attack, as well as addressing an HTTP/2 weakness that has also been exploited in the wild.…

☐ β˜† βœ‡ The Register - Security

SBF on trial: The Python code that allegedly let Alameda hedge fund spend people's FTX deposits

October 10th 2023 at 21:21

And Caroline Ellison says she was told by Bankman-Fried to take $10B from customer accounts

At the fraud trial of former FTX head Sam Bankman-Fried, prosecutors presented the jury with Python code for the FTX backend that allowed flagged client accounts to spend money they didn't have on the cryptocurrency exchange.…

☐ β˜† βœ‡ The Register - Security

HTTP/2 'Rapid Reset' zero-day exploited in biggest DDoS deluge seen yet

October 10th 2023 at 20:37

Botnet storm drowned last record with 398 million requests per second

A zero-day vulnerability in the HTTP/2 protocol was exploited to launch the largest distributed denial-of-service (DDoS) attack on record, according to Cloudflare.…

☐ β˜† βœ‡ The Register - Security

Mirai reloads exploit arsenal as botnet embarks on another expansion drive

October 10th 2023 at 18:15

With 13 new payloads it's the biggest update to the botnet in months

The infamous Mirai botnet was spotted by researchers who say it is spinning up again, this time with an "aggressively updated arsenal of exploits."…

☐ β˜† βœ‡ The Register - Security

Researcher bags two-for-one deal on Linux bugs while probing GNOME component

October 10th 2023 at 16:01

One-click exploit could potentially affect most major distros

Researchers discovered a high-severity remote code execution (RCE) vulnerability in an inherent component of GNOME-based Linux distros, potentially impacting a huge number of users.…

☐ β˜† βœ‡ The Register - Security

Fresh curl tomorrow will patch 'worst' security flaw in ages

October 10th 2023 at 14:30

It’s bad, folks. Pair of CVEs incoming on October 11

Updated Start your patch engines – a new version of curl is due tomorrow that addresses a pair of flaws, one of which lead developer Daniel Stenberg describes as "probably the worst curl security flaw in a long time."…

☐ β˜† βœ‡ The Register - Security

Ransomware attacks register record speeds thanks to success of infosec industry

October 10th 2023 at 08:30

Dwell times drop to hours rather than days for the first time

The time taken by cyber attackers between gaining an initial foothold in a victim's environment and deploying ransomware has fallen to 24 hours, according to a study.…

☐ β˜† βœ‡ The Register - Security

Exercise Cyber Star tests Singapore response

October 10th 2023 at 02:31

How SANS is helping boost the island’s defenses against whole-of-nation cyber attacks

Sponsored The cyber attack which culminated in the personal details of 1.5m patients being compromised after hackers broke into the databases of SingHealth in 2018 provides a stark illustration of why organizations in Singapore need to remain vigilant and well protected against further incidents.…

☐ β˜† βœ‡ The Register - Security

DoJ: Ex-soldier tried to pass secrets to China after seeking a 'subreddit about spy stuff'

October 9th 2023 at 15:15

FBI agent claims sergeant with top clearance offered access to DoD tech systems

A former US Army Sergeant with Top Secret US military clearance created a Word document entitled "Important Information to Share with Chinese Government," according to an FBI agent's sworn declaration.…

❌