FreshRSS

πŸ”’
☐ β˜† βœ‡ The Register - Security

Cloud engineer wreaks havoc on bank network after getting fired

December 12th 2023 at 19:43

Now he's got two years behind bars to think about his bad choices

An ex-First Republic Bank cloud engineer was sentenced to two years in prison for causing more than $220,000 in damage to his former employer's computer network after allegedly using his company-issued laptop to watch pornography.…

☐ β˜† βœ‡ The Register - Security

Discord in the ranks: Lone Airman behind top-secret info leak on chat platform

December 12th 2023 at 18:00

Poor cybersecurity hygiene in the military? Surely not!

There was only one US Air National Guardsman behind the leak of top-secret US military documents on Discord, but his chain of command bears some responsibility for letting it happen on their watch.…

☐ β˜† βœ‡ The Register - Security

Northern Ireland cops count human cost of August data breach

December 12th 2023 at 13:46

Officers potentially targeted by dissidents can't afford to relocate for their safety, while others seek support to change their names

An official review of the Police Service of Northern Ireland's (PSNI) August data breach has revealed the full extent of the impact on staff.…

☐ β˜† βœ‡ The Register - Security

BlackBerry squashes plan to spin out its IoT biz

December 12th 2023 at 08:23

Board and incoming CEO decide reorganizing is better than splitting

BlackBerry has decided its plan to split into two separate companies is not a good idea and will instead reorganize itself into two independent divisions.…

☐ β˜† βœ‡ The Register - Security

Interpol moves against human traffickers who enslave people to scam you online

December 12th 2023 at 06:30

Scum lure folks with promises of good jobs in crypto and then won't let them leave

Hundreds of suspected people smugglers have been arrested, and 163 potential victims rescued from servitude, as part of an Interpol-coordinated operation dubbed "Turquesa V" that targeted cyber criminals who lure workers into servitude to carry out their scams.…

☐ β˜† βœ‡ The Register - Security

Proposed US surveillance regime would enlist more businesses

December 12th 2023 at 01:45

Expanded service provider definition could force cafes and hotels to spy for the feds

Many US businesses may be required to assist in government-directed surveillance – depending upon which of two reform bills before Congress is approved.…

☐ β˜† βœ‡ The Register - Security

2.5M patients infected with data loss in Norton Healthcare ransomware outbreak

December 11th 2023 at 20:01

AlphV lays claims to the intrusion

Norton Healthcare, which runs eight hospitals and more than 30 clinics in Kentucky and Indiana, has admitted crooks may have stolen 2.5 million people's most sensitive data during a ransomware attack in May.…

☐ β˜† βœ‡ The Register - Security

Memory-safe languages so hot right now, agrees Lazarus Group as it slings DLang malware

December 11th 2023 at 18:08

Latest offensive cyber group to switch to atypical programming for payloads

Research into Lazarus Group's attacks using Log4Shell has revealed novel malware strains written in an atypical programming language.…

☐ β˜† βœ‡ The Register - Security

Two years on, 1 in 4 apps still vulnerable to Log4Shell

December 11th 2023 at 15:01

Lack of awareness still blamed for patching apathy despite it being among most infamous bugs of all time

Two years after the Log4Shell vulnerability in the open source Java-based Log4j logging utility was disclosed, circa one in four applications are dependent on outdated libraries, leaving them open to exploitation.…

☐ β˜† βœ‡ The Register - Security

Read the clouds, reduce the cyber risk

December 11th 2023 at 13:52

Why a one-size- fits- all approach to cloud security is unlikely to work in multi-cloud deployments

Webinar In the natural world, there are ten different kinds of cloud - a rare simplicity in meteorological terms. But in our global business environment, there's no single defining feature to aid classification.…

☐ β˜† βœ‡ The Register - Security

23andMe responds to breach with new suit-limiting user terms

December 11th 2023 at 11:46

Also: 'well-known Bay Area tech' firm's laptops stolen and check out some critical vulns

Security in brief The saga of 23andMe's mega data breach has reached something of a conclusion, with the company saying its probe has determined millions of leaked records originated from illicit break-ins into just 14,000 accounts.…

☐ β˜† βœ‡ The Register - Security

VictoriaMetrics takes organic growth over investor pressure

December 11th 2023 at 10:15

Keeping the lights on with an enterprise product while staying true to your roots

Interview Monitoring biz VictoriaMetrics is relatively unusual in its field. It is yet to accept external investment, preferring instead to try to grow organically rather than being forced to through a private equity meat grinder by committing to grow by X every year until the investor exits.…

☐ β˜† βœ‡ The Register - Security

Hollywood plays unwitting Cameo in Kremlin plot to discredit Zelensky

December 9th 2023 at 11:28

Microsoft spots surge in pro-Russia exploits of video platform to spread propaganda

An unknown pro-Russia influence group spent time recruiting unwitting Hollywood actors to assist in smear campaigns against Ukraine and its president Volodymyr Zelensky.…

☐ β˜† βœ‡ The Register - Security

Competing Section 702 surveillance bills on collision path for US House floor

December 8th 2023 at 22:30

End-of-year deadline looms on US surveillance

Two competing bills to reauthorize America's FISA Section 702 spying powers advanced in the House of Representatives committees this week, setting up Congress for a battle over warrantless surveillance before the law lapses in the New Year.…

☐ β˜† βœ‡ The Register - Security

That call center tech scammer could be a human trafficking victim

December 8th 2023 at 15:25

Interpol increasingly concerned as abject abuse of victims scales far beyond Asia origins

Human trafficking for the purposes of populating cyber scam call centers is expanding beyond southeast Asia, where the crime was previously isolated.…

☐ β˜† βœ‡ The Register - Security

Polish train maker denies claims its software bricked rolling stock maintained by competitor

December 8th 2023 at 06:30

Says it was probably hacked, which isn't good news either

A trio of Polish security researchers claim to have found that trains built by Newag SA contain software that sabotages them if the hardware is serviced by competitors.…

☐ β˜† βœ‡ The Register - Security

Five Eyes nations warn Moscow's mates at the Star Blizzard gang have new phishing targets

December 8th 2023 at 01:31

The Russians are coming! Err, they've already infiltrated UK, US inboxes

Russia-backed attackers have named new targets for their ongoing phishing campaigns, with defense-industrial firms and energy facilities now in their sights, according to agencies of the Five Eyes alliance.…

☐ β˜† βœ‡ The Register - Security

Attacks abuse Microsoft DHCP to spoof DNS records and steal secrets

December 7th 2023 at 22:11

Akamai says it reported the flaws to Microsoft. Redmond shrugged

A series of attacks against Microsoft Active Directory domains could allow miscreants to spoof DNS records, compromise Active Directory and steal all the secrets it stores, according to Akamai security researchers.…

☐ β˜† βœ‡ The Register - Security

US and EU infosec authorities pen intel-sharing pact

December 7th 2023 at 18:28

As Cyber Solidarity Act edges closer to full adoption in Europe

The US Cybersecurity and Infrastructure Security Agency (CISA) has signed a working arrangement with its EU counterparts to increase cross-border information sharing and more to tackle criminals.…

☐ β˜† βœ‡ The Register - Security

Belgian man charged with smuggling sanctioned military tech to Russia and China

December 7th 2023 at 07:30

Indictments allege plot to shift FPGAs, accelerometers, and spycams

A Belgian man has been arrested and charged for his role in a years-long smuggling scheme to export military-grade electronics from the US to Russia and China.…

☐ β˜† βœ‡ The Register - Security

Australia building 'top secret' cloud to catch up and link with US, UK intel orgs

December 7th 2023 at 04:33

Plans to share 'vast amounts of data' – very carefully

Australia is building a top-secret cloud to host intelligence data and share it with the US and UK, which have their own clouds built for the same purpose.…

☐ β˜† βœ‡ The Register - Security

Apple and some Linux distros are open to Bluetooth attack

December 6th 2023 at 20:47

Issue has been around since at least 2012

A years-old Bluetooth authentication bypass vulnerability allows miscreants to connect to Apple, Android and Linux devices and inject keystrokes to run arbitrary commands, according to a software engineer at drone technology firm SkySafe.…

☐ β˜† βœ‡ The Register - Security

Locking down the edge

December 6th 2023 at 16:09

Watch this webinar to find out how Zero Trust fits into the edge security ecosystem

Sponsored Post Edge security is a growing headache. The attack surface is expanding as more operational functions migrate out of centralized locations and into distributed sites and devices.…

☐ β˜† βœ‡ The Register - Security

A year on, CISA realizes debunked vuln actually a dud and removes it from must-patch list

December 6th 2023 at 14:45

Apparently no one thought to check if this D-Link router 'issue' was actually exploitable

A security vulnerability previously added to CISA's Known Exploited Vulnerability catalog (KEV), which was recognized by CVE Numbering Authorities (CNA), and included in reputable threat reports is now being formally rejected by infosec organizations.…

☐ β˜† βœ‡ The Register - Security

Shielding the data that drives AI

December 6th 2023 at 10:23

Why we need the confidence to deploy secure, compliant AI-powered applications and workloads

Sponsored Feature Every organisation must prioritise the protection of mission critical data, applications and workloads or risk disaster in the face of an ever-widening threat landscape.…

☐ β˜† βœ‡ The Register - Security

Atlassian security advisory reveals four fresh critical flaws – in mail with dead links

December 6th 2023 at 06:57

Bitbucket, Confluence and Jira all in danger, again. Sigh

Atlassian has emailed its customers to warn of four critical vulnerabilities, but the message had flaws of its own – the links it contained weren't live for all readers at the time of despatch.…

☐ β˜† βœ‡ The Register - Security

Microsoft issues deadline for end of Windows 10 support – it's pay to play for security

December 6th 2023 at 06:31

Limited options will be available into 2028, for an undisclosed price

Microsoft on Tuesday warned that full security support for Windows 10 will end on October 14, 2025, but offered a lifeline for customers unable or unwilling to upgrade two years hence.…

☐ β˜† βœ‡ The Register - Security

Cisco intros AI to find firewall flaws, warns this sort of thing can't be free

December 6th 2023 at 04:29

Predicts cyber crims will find binary brainboxes harder to battle

Cisco's executive veep for security Jeetu Patel has predicted that AI will change the infosec landscape, but that end users will eventually pay for the privilege of having a binary brainbox by their side when they go into battle.…

☐ β˜† βœ‡ The Register - Security

Fancy Bear goes phishing in US, European high-value networks

December 6th 2023 at 00:15

GRU-linked crew going after our code warns Microsoft - Outlook not good

Fancy Bear, the Kremlin's cyber-spy crew, has been exploiting two previously patched bugs for large-scale phishing campaigns against high-value targets – like government, defense, and aerospace agencies in the US and Europe – since March, according to Microsoft. …

☐ β˜† βœ‡ The Register - Security

CISA details twin attacks on federal servers via unpatched ColdFusion flaw

December 5th 2023 at 17:40

Tardy IT admins likely to get a chilly reception over the lack of updates

CISA has released details about a federal agency that recently had at least two public-facing servers compromised by attackers exploiting a critical Adobe ColdFusion vulnerability.…

☐ β˜† βœ‡ The Register - Security

DSPM deep dive: debunking data security myths

December 5th 2023 at 16:21

To maintain a strong data security posture, you must protect the data where it lives

Partner Content There are plenty of technology acronyms in the alphabet soup of the cybersecurity industry, but DSPM is the latest one leading the charge; its recent buzz has brought scrutiny to various security concepts that have cluttered the meaning behind data security posture management.…

☐ β˜† βœ‡ The Register - Security

BlackCat ransomware crims threaten to directly extort victim's customers

December 5th 2023 at 12:30

Accounting software firm Tipalti says it’s investigating alleged break-in of its systems

The AlphV/BlackCat ransomware group said it plans to "go direct" to the clients of a firm it allegedly attacked to extort them, claiming to have infiltrated the systems of accounting software vendor Tipalti.…

☐ β˜† βœ‡ The Register - Security

It's ba-ack... UK watchdog publishes age verification proposals

December 5th 2023 at 10:22

Won't somebody think of the children?

The UK's communications regulator has laid out guidance on how online services might perform age checks as part of the Online Safety Act.…

☐ β˜† βœ‡ The Register - Security

UK government denies China/Russia nuke plant hack claim

December 5th 2023 at 06:30

Report suggests Sellafield compromised since 2015, response seems worryingly ignorant of Stuxnet

The government of the United Kingdom has issued a strongly worded denial of a report that the Sellafield nuclear complex has been compromised by malware for years.…

☐ β˜† βœ‡ The Register - Security

US warns Iranian terrorist crew broke into 'multiple' US water facilities

December 4th 2023 at 23:30

There's a war on and critical infrastructure operators are still using default passwords

Iran-linked cyber thugs have exploited Israeli-made programmable logic controllers (PLCs) used in "multiple" water systems and other operational technology environments at facilities across the US, according to multiple law enforcement agencies .…

☐ β˜† βœ‡ The Register - Security

Hershey phishes! Crooks snarf chocolate lovers' creds

December 4th 2023 at 19:15

Stealing Kit Kat maker's data?! Give me a break

There's no sugarcoating this news: The Hershey Company has disclosed cyber crooks gobbled up 2,214 people's financial information following a phishing campaign that netted the chocolate maker's data.…

☐ β˜† βœ‡ The Register - Security

Two new versions of OpenZFS fix long-hidden corruption bug

December 4th 2023 at 16:15

Version 2.2.2 and also 2.1.14, showing that this wasn't a new issue in the latest release

The bug that was very occasionally corrupting data on file copies in OpenZFS 2.2.0 has been identified and fixed, and there's a fix for the previous OpenZFS release too.…

☐ β˜† βœ‡ The Register - Security

Exposed Hugging Face API tokens offered full access to Meta's Llama 2

December 4th 2023 at 14:00

With more than 1,500 tokens exposed, research highlights importance of securing supply chains in AI and ML

Updated The API tokens of tech giants Meta, Microsoft, Google, VMware, and more have been found exposed on Hugging Face, opening them up to potential supply chain attacks. …

☐ β˜† βœ‡ The Register - Security

EU lawmakers finalize cyber security rules that panicked open source devs

December 4th 2023 at 06:01

PLUS: Montana TikTok ban ruled unconstitutional; Dollar Tree employee data stolen; critical vulnerabilities

Infosec in brief The European Union’s Parliament and Council have reached an agreement on the Cyber Resilience Act (CRA), setting the long-awaited security regulation on a path to final approval and adoption, along with new rules exempting open source software.…

☐ β˜† βœ‡ The Register - Security

New Relic's cyber-something revealed as attack on staging systems, some users

December 4th 2023 at 04:27

Ongoing investigation found evidence of stolen employee creds and social engineering

Nine days after issuing a vaguely worded warning about a possible cyber security incident, web tracking and analytics outfit New Relic has revealed a two-front attack.…

☐ β˜† βœ‡ The Register - Security

Scores of US credit unions offline after ransomware infects backend cloud outfit

December 2nd 2023 at 00:01

Supply chain attacks: The gift that keeps on giving

A ransomware infection at a cloud IT provider has disrupted services for 60 or so credit unions across the US, all of which were relying on the attacked vendor. …

☐ β˜† βœ‡ The Register - Security

Apple slaps patch on WebKit holes in iPhones and Macs amid fears of active attacks

December 1st 2023 at 21:31

Two CVEs can be abused to steal sensitive info or execute code

Apple has issued emergency fixes to plug security flaws in iPhones, iPads, and Macs that may already be under attack.…

☐ β˜† βœ‡ The Register - Security

UEFI flaws allow bootkits to pwn potentially hundreds of devices using images

December 1st 2023 at 20:12

Exploits bypass most secure boot solutions from the biggest chip vendors

Hundreds of consumer and enterprise devices are potentially vulnerable to bootkit exploits through unsecured BIOS image parsers.…

☐ β˜† βœ‡ The Register - Security

US readies prison cell for another Russian Trickbot developer

December 1st 2023 at 15:08

Hunt continues for the other elusive high-ranking members

Another member of the Trickbot malware crew now faces a lengthy prison sentence amid US law enforcement's ongoing search for its leading members.…

☐ β˜† βœ‡ The Register - Security

Regulator says stranger entered hospital, treated a patient, took a document ... then vanished

December 1st 2023 at 10:15

Scottish health group to tweak security checks, access authorization to avoid a repeat

NHS Fife is on the wrong end of a stern ticking off by Britain's data regulator after it made a howling privacy error that aided an as yet unknown person who had entered a hospital ward only to walk off with data on 14 patients.…

☐ β˜† βœ‡ The Register - Security

Interpol makes first border arrest using Biometric Hub to ID suspect

December 1st 2023 at 07:25

Global database of faces and fingerprints proves its worth

European police have for the first time made an arrest after remotely checking Interpol's trove of biometric data to identify a suspected smuggler.…

☐ β˜† βœ‡ The Register - Security

Today's 'China is misbehaving online' allegations come from Google, Meta

December 1st 2023 at 02:59

Zuck boots propagandists, Big G finds surge of action directed at Taiwan

Meta and Google have disclosed what they allege are offensive cyber ops conducted by China.…

☐ β˜† βœ‡ The Register - Security

Uh-oh, update Google Chrome – exploit already out there for one of these 6 security holes

November 30th 2023 at 20:45

Plus: 3 critical CVEs in Zyxel NAS devices

Google has rolled out six Chrome security fixes including one emergency patch for a bug for which exploit code is already out there. You're encouraged to thus grab the latest updates for the browser.…

☐ β˜† βœ‡ The Register - Security

Admin of $19M marketplace that sold social security numbers gets 8 years in jail

November 30th 2023 at 18:30

24 million Americans thought to have had their personal data stolen and sold for pennies

A Ukrainian national is facing an eight year prison sentence for running an online marketplace that sold the personal data of approximately 24 million US citizens.…

☐ β˜† βœ‡ The Register - Security

Black Basta ransomware operation nets over $100M from victims in less than two years

November 30th 2023 at 13:15

Assumed Conti offshoot averages 7 figures for each successful attack but may have issues with, er, 'closing deals'

The Black Basta ransomware group has reportedly generated upwards of $100 million in revenue since it started operations in April 2022.…

☐ β˜† βœ‡ The Register - Security

Locking down Industrial Control Systems

November 30th 2023 at 08:47

SANS unveils online hub with valuable tools and information for cybersecurity professionals defending ICS

Sponsored Post Industrial Control Systems (ICS) which can automate processes, increase productivity and reduce labour costs, are rapidly gaining worldwide enterprise traction.…

☐ β˜† βœ‡ The Register - Security

Weak session keys let snoops take a byte out of your Bluetooth traffic

November 30th 2023 at 07:32

BLUFFS spying flaw present in iPhones, ThinkPad, plenty of chipsets

Multiple Bluetooth chips from major vendors such as Qualcomm, Broadcom, Intel, and Apple are vulnerable to a pair of security flaws that allow a nearby miscreant to impersonate other devices and intercept data.…

☐ β˜† βœ‡ The Register - Security

US lawmakers have Chinese LiDAR on their threat-detection radar

November 30th 2023 at 02:29

Amid fears Beijing could harvest spatial data, letter suggests Huawei-style bans may be needed

A US congressional committee has questioned whether Chinese-made Light Detection and Ranging (LiDAR) devices might have a negative impact on national security, and suggested they may therefore be worthy of the same bans that prevent stateside adoption of other tech.…

☐ β˜† βœ‡ The Register - Security

Rogue ex-Motorola techie admits cyberattack on former employer, passport fraud

November 30th 2023 at 01:15

Pro tip: Don't use your new work email to phish your old firm

An ex-Motorola Solutions technician in the US has admitted he tried to fraudulently obtain a passport while awaiting trial for a cyberattack on his former employer.…

☐ β˜† βœ‡ The Register - Security

Uncle Sam probes cyberattack on Pennsylvania water system by suspected Iranian crew

November 29th 2023 at 21:16

CISA calls for stronger IT defenses as Texas district also hit by ransomware crew

CISA is investigating a cyberattack against a Pennsylvania water authority by suspected Iranian miscreants. The intrusion forced operators to switch a pumping station to manual control.…

☐ β˜† βœ‡ The Register - Security

Okta data breach dilemma dwarfs earlier estimates

November 29th 2023 at 17:01

All customer support users told their info was accessed after analysis oversight

Okta has admitted that the number of customers affected by its October customer support system data breach is far greater than previously thought.…

☐ β˜† βœ‡ The Register - Security

British Library begins contacting customers as Rhysida leaks data dump

November 29th 2023 at 12:30

CRM databases were accessed and library users are advised to change passwords

The Rhysida ransomware group has published most of the data it claimed to have stolen from the British Library a month after the attack was disclosed.…

☐ β˜† βœ‡ The Register - Security

UK government rings the death knell for SIM farms

November 29th 2023 at 11:01

Acts under the guise of protecting the public from fraud, yet history suggests Home Office has other motives

The UK government plans to introduce new legislation to ban SIM farms, which it views as a widely abused means for carrying out cyber fraud.…

☐ β˜† βœ‡ The Register - Security

Brit borough council apologizes for telling website users to disable HTTPS

November 29th 2023 at 09:30

Planning portal back online with a more secure connection

Reading Borough Council has securely restored its planning portal after facing criticism for recommending questionable tech security practices to users.…

☐ β˜† βœ‡ The Register - Security

Japan's space agency suffers cyber attack, points finger at Active Directory

November 29th 2023 at 06:57

JAXA is having a tough time in cyberspace and outer space, the latter thanks to an electrical glitch

Japan's Space Exploration Agency (JAXA) has reported a cyber incident.…

❌