FreshRSS

πŸ”’
☐ β˜† βœ‡ The Register - Security

Impatient LockBit says it's leaked 50GB of stolen Boeing files after ransom fails to land

November 10th 2023 at 20:21

Aerospace titan pores over data to see if dump is legit

The LockBit crew is claiming to have leaked all of the data it stole from Boeing late last month, after the passenger jet giant apparently refused to pay the ransom demand.…

☐ β˜† βœ‡ The Register - Security

Poloniex crypto-exchange offers 5% cut to thieves if they return that $120M they nicked

November 10th 2023 at 18:51

White hat bounty looks more like a beg bounty

The founder of the Poloniex has offered to pay off thieves who drained an estimated $120 million of user funds from the cryptocurrency exchange in a raid on Friday.…

☐ β˜† βœ‡ The Register - Security

Strangely enough, no one wants to buy a ransomware group that has cops' attention

November 10th 2023 at 15:36

Ransomed.vc shuts after 20% discount fails to entice bids

Short-lived ransomware outfit Ransomed.vc claims to have shut down for good after a number of suspected arrests.…

☐ β˜† βœ‡ The Register - Security

China's top bank ICBC hit by ransomware, derailing global trades

November 10th 2023 at 08:00

CitrixBleed patch has been available for around a month

China's largest bank, ICBC, was hit by ransomware that resulted in disruption of financial services (FS) systems on Thursday Beijing time, according to a notice on its website.…

☐ β˜† βœ‡ The Register - Security

Downfall fallout: Intel knew AVX chips were insecure and did nothing, lawsuit claims

November 9th 2023 at 22:20

Billions of data-leaking processors sold despite warnings and patch just made them slower, punters complain

Intel has been sued by a handful of PC buyers who claim the x86 goliath failed to act when informed five years ago about faulty chip instructions that allowed the recent Downfall vulnerability, and during that period sold billions of insecure chips.…

☐ β˜† βœ‡ The Register - Security

SolarWinds says SEC sucks: Watchdog 'lacks competence' to regulate cybersecurity

November 9th 2023 at 17:03

IT software slinger publishes fierce response to lawsuit brought last month

SolarWinds has come out guns blazing to defend itself following the US Securities and Exchange Commission's announcement that it will be suing both the IT software maker and its CISO over the 2020 SUNBURST cyberattack.…

☐ β˜† βœ‡ The Register - Security

MOVEit cybercriminals unearth fresh zero-day to exploit on-prem SysAid hosts

November 9th 2023 at 12:36

Second novel zero-day exploited by Lace Tempest this year offers notable demonstration of skill, especially for a ransomware affiliate

The cybercriminals behind the stream of MOVEit attacks from earlier this year are making use of a zero-day vulnerability in on-prem instances of IT service and help desk software-slinger SysAid.…

☐ β˜† βœ‡ The Register - Security

Russia's Sandworm – not just missile strikes – to blame for Ukrainian power blackouts

November 9th 2023 at 08:00

Online attack coincided with major military action, Mandiant says

Blackouts in Ukraine last year were not just caused by missile strikes on the nation but also by a seemingly coordinated cyberattack on one of its power plants. That's according to Mandiant's threat intel team, which said Russia's Sandworm crew was behind the two-pronged power-outage and data-wiping attack.…

☐ β˜† βœ‡ The Register - Security

What to do with a cloud intrusion toolkit in 2023? Slap a chat assistant on it, duh

November 9th 2023 at 06:56

Don't worry, this half-baked Python script is for educational purposes onl-hahaha

Infosec bods have detailed an underground cybersecurity tool dubbed Predator AI that not only can be used to compromise poorly secured cloud services and web apps, but has an optional chat-bot assistant that only kinda works.…

☐ β˜† βœ‡ The Register - Security

Microsoft, Meta detail plans to fight election disinformation in 2024

November 8th 2023 at 19:01

Strategies differ, though both have gaps that could hurt efficacy

Microsoft and Meta have very different initiatives to combat misinformation in 2024, slated to be a busy election year all over the globe, but whether they'll be effective is another issue.…

☐ β˜† βœ‡ The Register - Security

Atlassian cranks up the threat meter to max for Confluence authorization flaw

November 8th 2023 at 14:00

Attackers secure admin rights after vendor said they could only steal data

Atlassian reassessed the severity rating of the recent improper authorization vulnerability in Confluence Data Center and Server, raising the CVSS score from 9.1 to a maximum of 10.…

☐ β˜† βœ‡ The Register - Security

Monero Project admits thieves stole 6-figure sum from a wallet in mystery breach

November 8th 2023 at 11:46

It's the latest in a string of unusual wallet-draining attacks that began in April

The Monero Project is admitting that one of its wallets was drained by an unknown source in September, losing the equivalent of around $437,000 at today's exchange rate.…

☐ β˜† βœ‡ The Register - Security

Preventing data theft with ADX technology

November 8th 2023 at 09:17

Ensuring data stays secure even after cyberattack infiltration

Webinar Daily incursions are underway with the aim of removing every bit of data that you've got - the cyber criminals' aim is to break in and get out again laden with digital booty.…

☐ β˜† βœ‡ The Register - Security

Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections

November 8th 2023 at 08:27

EFF warns incoming rules may return web 'to the dark ages of 2011'

Lawmakers in Europe are expected to adopt digital identity rules that civil society groups say will make the internet less secure and open up citizens to online surveillance.…

☐ β˜† βœ‡ The Register - Security

Microsoft likens MFA to 1960s seatbelts, buckles admins in yet keeps eject button

November 7th 2023 at 17:45

Admins have 90 days to opt out before MFA is deployed automatically

Microsoft is introducing three Conditional Access policies for sysadmins as it continues to promote the implementation of multi-factor authentication (MFA) in organizations.…

☐ β˜† βœ‡ The Register - Security

UK may demand tech world tell it about upcoming security features

November 7th 2023 at 16:34

Campaigners say proposals to reform laws are 'dangerous' and an attack on safety

The UK government has set in train plans to introduce legislation requiring tech companies to let it know when they plan to introduce new security technologies and could potentially force them to disable when required.…

☐ β˜† βœ‡ The Register - Security

Fresh find shines new light on North Korea’s latest macOS malware

November 7th 2023 at 14:44

Months of work reveals how this tricky malware family targets... the financial services sector

A brand-new macOS malware strain from North Korean state-sponsored hackers has been spotted in the wild.…

☐ β˜† βœ‡ The Register - Security

Woman jailed after RentaHitman.com assassin turned out to be – surprise – FBI

November 7th 2023 at 00:29

18 months in the slammer no laughing matter, but the rest... maybe

A 34-year-old woman has been jailed for 18 months after trying to use Rentahitman.com – no, really – to pay a contract killer to eliminate a rival she was beefing with. Her would-be assassin-for-hire unsurprisingly turned out to be an FBI agent.…

☐ β˜† βœ‡ The Register - Security

ICE faces heat after agents install thousands of personal apps, VPNs on official phones

November 6th 2023 at 22:33

Audit: Craptastic security potentially put govt info in hands of enemies

America's immigration cops have pushed back against an official probe that concluded their lax mobile device security potentially put sensitive government information at risk of being stolen by foreign snoops.…

☐ β˜† βœ‡ The Register - Security

US slaps sanctions on accused fave go-to money launderer of Russia's rich

November 6th 2023 at 16:15

And that includes ransomware crims, claims US of alleged sanctions-buster

A Russian woman the US accuses of being a career money launderer is the latest to be sanctioned by the country for her alleged role in moving hundreds of millions of dollars on behalf of oligarchs and ransomware criminals.…

☐ β˜† βœ‡ The Register - Security

Okta October breach affected 134 orgs, biz admits

November 6th 2023 at 14:01

Plus: CVSS 4.0 is here, this week's critical vulns, and 'incident' hit loan broker promises no late fees. Generous

Infosec in brief Okta has confirmed details of its October breach, reporting that the incident led to the compromise of files belonging to 134 customers, "or less than 1 percent of Okta customers." …

☐ β˜† βœ‡ The Register - Security

Securing frontline Operational Technology environments

November 6th 2023 at 11:35

How Britvic outlawed security blind spots

Webinar Organisations in multiple industries often face risks which can severely impact their operational resilience. Cyber criminals like to use ransomware and vulnerable third-party connections to hijack operational technology (OT) systems which can stop production in manufacturing environments, for example.…

☐ β˜† βœ‡ The Register - Security

'Corrupt' cop jailed for tipping off pal to EncroChat dragnet

November 4th 2023 at 07:37

Taking selfie with 'official sensitive' doc wasn't smartest idea, either

A British court has sentenced a "corrupt" police analyst to almost four years behind bars for tipping off a friend that officers had compromised the EncroChat encrypted messaging app network.…

☐ β˜† βœ‡ The Register - Security

81K people's sensitive info feared stolen from Hilb after email inboxes ransacked

November 3rd 2023 at 20:26

Credit card numbers, security codes, SSNs, passwords, PINs? Yikes!

Hilb Group has warned more than 81,000 people that around the start of 2023 criminals broke into the work email accounts of its employees and may have stolen a bunch of sensitive personal information.…

☐ β˜† βœ‡ The Register - Security

Ex-GCHQ software dev jailed for stabbing NSA staffer

November 3rd 2023 at 19:02

Terrorist ideology suspected to be motivation

A former software developer for Britain's cyberspy agency is facing years in the slammer after being sentenced for stabbing a National Security Agency (NSA) official multiple times.…

☐ β˜† βœ‡ The Register - Security

Microsoft pins hopes on AI once again – this time to patch up Swiss cheese security

November 3rd 2023 at 16:02

Secure Future Initiative needed in wake of tech evolution and unrelenting ransomware criminality

Microsoft has made fresh commitments to harden the security of its software and cloud services after a year in which numerous members of the global infosec community criticized the company's tech defenses.…

☐ β˜† βœ‡ The Register - Security

UK data watchdog fines three text spammers for flouting electronic marketing rules

November 3rd 2023 at 11:17

'High-pressure' sales tactics targeted people registered with Telephone Preference Service

A "debt management company" is itself facing a bill from Britain's data regulator for sending hundreds of thousands of text messages to households that opted not to receive marketing junk mail.…

☐ β˜† βœ‡ The Register - Security

Dirty dancing grabs the attention of China's cyberspace regulators

November 2nd 2023 at 02:45

Alibaba service fined as Beijing calls for online platforms to name major creators and deploy kid-mode services

China's Cyberspace Administration (CAC) has punished Alibaba-owned search engine Quark and livestreaming platform NetEase for content it deemed vulgar.…

☐ β˜† βœ‡ The Register - Security

FTX crypto-villain Sam Bankman-Fried convicted on all charges

November 3rd 2023 at 01:10

Jury took just four hours to reach guilty verdicts

Sam Bankman-Fried, the founder and former CEO of crypto exchange FTX and trading firm Alameda Research, has been found guilty of seven criminal charges.…

☐ β˜† βœ‡ The Register - Security

Infosec pros can secure IT, but have harder time securing job satisfaction

November 2nd 2023 at 18:00

Industry facing burnout scare as workplace issues snowball

The proportion of cybersecurity professionals reporting low "happiness ratings" has risen sharply over the last 12 months, raising concerns about increasing burnout rates in the industry.…

☐ β˜† βœ‡ The Register - Security

Critical Apache ActiveMQ flaw under attack by 'clumsy' ransomware crims

November 2nd 2023 at 17:15

Over a week later and barely any patches for the 10/10 vulnerability have been applied

Security researchers have confirmed that ransomware criminals are capitalizing on a maximum-severity vulnerability in Apache ActiveMQ.…

☐ β˜† βœ‡ The Register - Security

Okta tells 5,000 of its own staff that their data was accessed in third-party breach

November 2nd 2023 at 15:37

The hits keep on coming for troubled ID management biz

Updated Okta has sent out breach notifications to almost 5,000 current and former employees, warning them that miscreants breached one of its third-party vendors and stole a file containing staff names, social security numbers, and health or medical insurance plan numbers.…

☐ β˜† βœ‡ The Register - Security

Boeing acknowledges cyberattack on parts and distribution biz

November 2nd 2023 at 03:31

Won't say if it's LockBit, but LockBit appears to have claimed credit. Maybe payment, too

Boeing has acknowledged a cyber incident just days after ransomware gang LockBit reportedly exfiltrated sensitive data from the aerospace defence contractor.…

☐ β˜† βœ‡ The Register - Security

FBI boss: Taking away our Section 702 spying powers could be 'devastating'

November 2nd 2023 at 01:22

Of course, he would say that, wouldn't he?

As the expiration date for the Feds' Section 702 surveillance powers draws closer, FBI Director Christopher Wray has warned a US Senate committee that his agents may not be able to stop the next major cyberattack if lawmakers allow the contentious spying authorization to lapse.…

☐ β˜† βœ‡ The Register - Security

Ransomware crooks SIM swap medical research biz exec, threaten to leak stolen data

November 1st 2023 at 22:46

Advarra probes intrusion claims, says 'the matter is contained'

Ransomware crooks claim they've stolen data from a firm that helps other organizations run medical trials after one of its executives had their cellphone number and accounts hijacked.…

☐ β˜† βœ‡ The Register - Security

Mozi botnet murder mystery: China or criminal operators behind the kill switch?

November 1st 2023 at 20:00

Middle Kingdom or self-immolation - there are a couple of theories

The Mozi botnet has all but disappeared according to security folks who first noticed the prolific network's slowdown and then uncovered a kill switch for the IoT system. But they still have one unanswered question: "Who killed Mozi?"…

☐ β˜† βœ‡ The Register - Security

Feds collar suspected sanctions-busting Russian smugglers of US tech

November 1st 2023 at 18:29

Parts sent to Moscow allegedly found on Ukrainian battlefields

Three Russian nationals were arrested in New York yesterday on charges of moving electronics components worth millions to sanctioned entities in Russia, pieces of which were later recovered on battlefields in Ukraine.…

☐ β˜† βœ‡ The Register - Security

Critical vulnerability in F5 BIG-IP under active exploitation

November 1st 2023 at 16:14

Full extent of attacks unknown but telecoms thought to be especially exposed

Vulnerabilities in F5's BIG-IP suite are already being exploited after proof of concept (PoC) code began circulating online.…

☐ β˜† βœ‡ The Register - Security

Cybercrooks amp up attacks via macro-enabled XLL files

November 1st 2023 at 14:45

Neither Excel nor PowerPoint safe as baddies continue to find ways around protections

Cybercriminals are once again abusing macro-enabled Excel add-in (XLL) files in malware attacks at a vastly increased rate, according to new research.…

☐ β˜† βœ‡ The Register - Security

Get your very own ransomware empire on the cheap, while stocks last

November 1st 2023 at 11:48

RansomedVC owner takes to Telegram to flog criminal enterprise

The short-lived RansomedVC ransomware operation is being shopped around by its owner, who is claiming to offer a 20 percent discount just a day after first listing it for sale.…

☐ β˜† βœ‡ The Register - Security

Meeting the challenge of OT security

November 1st 2023 at 08:38

Learn how Britvic eliminates blind spots in Operational Technology systems

Webinar Cyberattacks on industrial control systems are becoming more common, and there isn't likely to be a let up any time soon.…

☐ β˜† βœ‡ The Register - Security

Indian politicians say Apple warned them of state-sponsored attacks

November 1st 2023 at 05:02

Nobody knows which state, but government never quite shrugged off claims it uses spyware

Indian politicians and media figures have reported that Apple has warned them their accounts may be under attack by state-sponsored actors.…

☐ β˜† βœ‡ The Register - Security

US officials close to persuading allies to not pay off ransomware crooks

October 31st 2023 at 22:49

'We're still in the final throes of getting every last member to sign'

Top White House officials are working to secure an agreement between almost 50 countries to not pay ransom demands to cybercriminals as the international Counter Ransomware Initiative (CRI) summit gets underway in Washington DC Tuesday.…

☐ β˜† βœ‡ The Register - Security

'Mass exploitation' of Citrix Bleed underway as ransomware crews pile in

October 31st 2023 at 20:45

At least two extortion gangs abusing CVE-2023-4966, we're told

Citrix Bleed, the critical information-disclosure bug that affects NetScaler ADC and NetScaler Gateway, is now under "mass exploitation," as thousands of Citrix NetScaler instances remain vulnerable, according to security teams.…

☐ β˜† βœ‡ The Register - Security

Now Russians accused of pwning JFK taxi system to sell top spots to cabbies

October 31st 2023 at 19:16

Big Apple unlikely to get a bite out of them at this rate, though

For a period of two years between September 2019 and September 2021, two Americans and two Russians allegedly compromising the taxi dispatch system at John F. Kennedy International Airport in New York to sell cabbies a place at the front of the dispatch line.…

☐ β˜† βœ‡ The Register - Security

Ace holed: Hardware store empire felled by cyberattack

October 31st 2023 at 17:33

US outfit scrambles to repair operations, restore processing of online orders

Ace Hardware appears to have been the latest organization to succumb to a cyberattack, judging by its website and a message from CEO John Venhuizen.…

☐ β˜† βœ‡ The Register - Security

Finance orgs have 30 days to confess cyber sins under incoming FTC rules

October 31st 2023 at 16:13

Follows similar efforts from the SEC and DHS in recent months

The US has approved mandatory data breach reporting requirements that impose a 30-day deadline for non-banking financial organizations to report incidents.…

☐ β˜† βœ‡ The Register - Security

Cybersecurity snafu sends British Library back to the Dark Ages

October 31st 2023 at 14:16

Internet, phone lines, websites, and more went down on Saturday morning

The British Library has confirmed to The Register that a "cyber incident" is the cause of a "major" multi-day IT outage.…

☐ β˜† βœ‡ The Register - Security

UK policing minister urges doubling down on face-scanning tech

October 31st 2023 at 12:30

'No question' it will solve more crimes, Tory MP claims

A UK minister for policing has called for forces to double their use of algorithmic-assisted facial recognition in a bid to snare more criminals.…

☐ β˜† βœ‡ The Register - Security

Meta's ad-free scheme dares you to buy your privacy back, one euro at a time

October 31st 2023 at 09:30

If you're in the EU, EEA, or Switzerland

From November, it will be possible to pay Meta to stop shoveling ads in your Instagram or Facebook feeds and slurping your data for marketing purposes so long as you live in the EU, EEA, or Switzerland.…

☐ β˜† βœ‡ The Register - Security

Stop what you’re doing and patch this critical Confluence flaw, warns Atlassian

October 31st 2023 at 05:05

Risk of β€˜significant data loss’ for on-prem customers

Atlassian has told customers they β€œmust take immediate action” to address a newly discovered flaw in its Confluence collaboration tool.…

☐ β˜† βœ‡ The Register - Security

Florida man jailed after draining $1M from victims in crypto SIM swap attacks

October 30th 2023 at 22:53

Not old enough to legally rent a car, old enough for a 30-month term

A 20-year-old Florida man has been sentenced to 30 months behind bars for his role in a SIM-swapping ring that stole nearly $1 million in cryptocurrency from dozens of victims.…

☐ β˜† βœ‡ The Register - Security

Unpatched NGINX ingress controller bugs can be abused to steal Kubernetes cluster secrets

October 30th 2023 at 20:00

Just tricks, no treats with these 3 vulns

Three unpatched high-severity bugs in the NGINX ingress controller can be abused by miscreants to steal credentials and other secrets from Kubernetes clusters. …

☐ β˜† βœ‡ The Register - Security

Cryptojackers steal AWS credentials from GitHub in 5 minutes

October 30th 2023 at 18:31

Researchers just scratching surface of their understanding of campaign dating back to 2020

Security researchers have uncovered a multi-year cryptojacking campaign they claim autonomously clones GitHub repositories and steals their exposed AWS credentials.…

☐ β˜† βœ‡ The Register - Security

Stanford schooled in cybersecurity after Akira claims ransomware attack

October 30th 2023 at 14:45

This marks the third criminal intrusion at the institution in as many years

Stanford University has confirmed it is "investigating a cybersecurity incident" after an attack last week by the Akira ransomware group.…

☐ β˜† βœ‡ The Register - Security

LockBit alleges it boarded Boeing, stole 'sensitive data'

October 30th 2023 at 02:30

ALSO: CISA begs for a consistent budget, Las Vegas school breach; Nigeria arrests six cyber princes, the week's critical vulnerabilities

Security In Brief Notorious ransomware gang LockBit has reportedly exfiltrated β€œa tremendous amount of sensitive data from aerospace outfit Boeing.…

☐ β˜† βœ‡ The Register - Security

Apple Private Wi-Fi hasn't worked for the past three years

October 27th 2023 at 22:30

Not exactly the MAC daddy

Three years after Apple introduced a menu setting called Private Wi-Fi Address, a way to spoof network identifiers called MAC addresses, the privacy protection may finally work as advertised, thanks to a software fix.…

☐ β˜† βœ‡ The Register - Security

F5 hurriedly squashes BIG-IP remote code execution bug

October 27th 2023 at 17:34

Fixes came earlier than scheduled as vulnerability became known to outsiders

F5 has issued a fix for a remote code execution (RCE) bug in its BIG-IP suite carrying a near-maximum severity score.…

☐ β˜† βœ‡ The Register - Security

Microsoft unveils shady shenanigans of Octo Tempest and their cyber-trickery toolkit

October 27th 2023 at 12:43

Gang thought to be behind attack on MGM Resorts has a skillset larger than most cybercrime groups in existence

Microsoft's latest report on "one of the most dangerous financial criminal groups" operating offers security pros an abundance of threat intelligence to protect themselves from its myriad tactics.…

☐ β˜† βœ‡ The Register - Security

King Charles III signs off on UK Online Safety Act, with unenforceable spying clause

October 27th 2023 at 09:51

It's now up to Ofcom to sort out this messy legislation

With the assent of King Charles, the United Kingdom's Online Safety Act has become law, one that the British government says will "make the UK the safest place in the world to be online."…

❌