FreshRSS

πŸ”’
☐ β˜† βœ‡ The Register - Security

Court hearings become ransomware concern after justice system breach

January 2nd 2024 at 16:15

From legal proceedings to potential YouTube fodder

The court system of Victoria, Australia, was subject to a suspected ransomware attack in which audiovisual recordings of court hearings may have been accessed.…

☐ β˜† βœ‡ The Register - Security

Crypto-crook Sam Bankman-Fried spared a second trial

January 2nd 2024 at 07:30

Eighth charge related to campaign contributions would just take too dang long

US prosecutors do not plan to proceed with a second trial of convicted and imprisoned crypto-villain Sam Bankman-Fried (SBF), according to a Southern District of New York court letter filed on December 29.…

☐ β˜† βœ‡ The Register - Security

CEO arranged his own cybersecurity, with predictable results

December 29th 2023 at 08:01

Cleaning up after hackers is easy compared to surviving the politics of consultancy

On Call It’s the last Friday of 2023, but because the need for tech support never goes away neither does On Call, The Register’s Friday column in which readers share their tales of being asked to fix the unfeasible, in circumstances that are often indefensible.…

☐ β˜† βœ‡ The Register - Security

A tale of 2 casino ransomware attacks: One paid out, one did not

December 28th 2023 at 17:05

What can be learned from MGM's and Caesars' infosec moves

Feature The same cybercrime crew broke into two high-profile Las Vegas casino networks over the summer, infected both with ransomware, and stole data belonging to tens of thousands of customers from the mega-resort chains.…

☐ β˜† βœ‡ The Register - Security

Kaspersky reveals previously unknown hardware 'feature' exploited in iPhone attacks

December 28th 2023 at 15:50

'This is no ordinary vulnerability' sec pros explain

Kaspersky's Global Research and Analysis Team (GReAT) has exposed a previously unknown "feature" in Apple iPhones that allowed malware to bypass hardware-based memory protection.…

☐ β˜† βœ‡ The Register - Security

Iranian cyberspies target US defense orgs with a brand new backdoor

December 23rd 2023 at 12:47

Also: International cops crackdown on credit card stealers and patch these critical vulns

Infosec in brief Iranian cyberspies are targeting defense industrial base organizations with a new backdoor called FalseFont, according to Microsoft.…

☐ β˜† βœ‡ The Register - Security

Cyber sleuths reveal how they infiltrate the biggest ransomware gangs

December 22nd 2023 at 15:55

How do you break into the bad guys' ranks? Master the lingo and research, research, research

Feature When AlphV/BlackCat's website went dark this month, it was like Chrimbo came early for cybersecurity defenders, some of whom seemingly believed law enforcement had busted one of the most menacing cyber criminal crews.…

☐ β˜† βœ‡ The Register - Security

Lapsus$ teen sentenced to indefinite detention in hospital for Nvidia, GTA cyberattacks

December 21st 2023 at 22:15

Arion Kurtaj will remain hospitalized until a mental health tribunal says he can leave

Two British teens who were members of the Lapsus$ gang have been sentenced for their roles in a cyber-crime spree that included compromising Uber, Nvidia, and fintech firm Revolut, and also blackmailing Grand Theft Auto maker Rockstar Games.…

☐ β˜† βœ‡ The Register - Security

Four in five Apache Struts 2 downloads are for versions featuring critical flaw

December 21st 2023 at 14:13

Seriously, people - please check the stuff you fetch more carefully

Security vendor Sonatype believes developers are failing to address the critical remote code execution (RCE) vulnerability in the Apache Struts 2 framework, based on recent downloads of the code.…

☐ β˜† βœ‡ The Register - Security

Mozilla decides Trusted Types is a worthy security feature

December 21st 2023 at 11:03

DOM-XSS attacks have become scarce on Google websites since TT debuted

Mozilla last week revised its position on a web security technology called Trusted Types, which it has decided to implement in its Firefox browser.…

☐ β˜† βœ‡ The Register - Security

Data loss prevention isn't rocket science, but NASA hasn't made it work in Microsoft 365

December 21st 2023 at 04:31

Privacy review finds breach response plan is a mess, training could be better, but protection regime mostly holds up

NASA's Office of Inspector General has run its eye over the aerospace agency's privacy regime and found plenty to like – but improvements are needed.…

☐ β˜† βœ‡ The Register - Security

Something nasty injected login-stealing JavaScript into 50K online banking sessions

December 20th 2023 at 23:45

Why keeping your PC secure and free of malware remains paramount

IBM Security has dissected some JavaScript code that was injected into people's online banking pages to steal their login credentials, saying 50,000 user sessions with more than 40 banks worldwide were compromised by the malicious software in 2023.…

☐ β˜† βœ‡ The Register - Security

Cybercrooks book a stay in hotel email inboxes to trick staff into spilling credentials

December 20th 2023 at 21:30

Research highlights how major attacks like those exploiting Booking.com are executed

Cybercriminals are preying on the inherent helpfulness of hotel staff during the sector's busy holiday season.…

☐ β˜† βœ‡ The Register - Security

Manchester's finest drowning in paperwork as Freedom of Information requests pile up

December 20th 2023 at 10:28

Enforcement notice issued months after data regulator schooled police force

Updated Greater Manchester Police (GMP) must clear the backlog of hundreds of Freedom of Information (FOI) Act requests – some years old – or find itself in contempt of court.…

☐ β˜† βœ‡ The Register - Security

SSH shaken, not stirred by Terrapin vulnerability

December 20th 2023 at 08:34

No need to panic, but grab those updates or mitigations anyway just to be safe

A vulnerability in the SSH protocol can be exploited by a well-placed adversary to weaken the security of people's connections, if conditions are right.…

☐ β˜† βœ‡ The Register - Security

Philippines, South Korea, Interpol cuff 3,500 suspected cyber scammers, seize $300M

December 20th 2023 at 00:32

Alleged crims used AI to pose as friends, family, romantic partners – and sold dodgy NFTs

A transnational police operation has resulted in the arrest of 3,500 alleged cybercriminals and the seizure of $300 million in cash and digital assets.…

☐ β˜† βœ‡ The Register - Security

Millions of Xfinity customers' info, hashed passwords feared stolen in cyberattack

December 19th 2023 at 20:43

35M-plus Comcast user IDs accessed by intruder via Citrix Bleed

Millions of Comcast Xfinity subscribers' personal data – including potentially their usernames, hashed passwords, contact details, and secret security question-answers – was likely stolen by one or more miscreants exploiting Citrix Bleed in October.…

☐ β˜† βœ‡ The Register - Security

Before you go away for Xmas: You've patched that critical Perforce Server hole, right?

December 19th 2023 at 19:57

Microsoft bug hunters highlight weaknesses in source-wrangling suite

Four vulnerabilities in Perforce Helix Core Server, including one critical remote code execution bug, should be patched "immediately," according to Microsoft, which spotted the flaws and disclosed them to the software vendor.…

☐ β˜† βœ‡ The Register - Security

FBI develops decryptor for BlackCat ransomware, seizes gang's website

December 19th 2023 at 14:59

Crims laugh it off and resume their activity

Updated The FBI created a decryption tool for the ransomware used by the gang known as BlackCat and/or AlphV, as part of a wider disruption campaign against the extortionists.…

☐ β˜† βœ‡ The Register - Security

Qakbot's backbot: FBI-led takedown keeps crims at bay for just 3 months

December 19th 2023 at 09:26

Experts say malware strain make take years to die off completely

Multiple sources are confirming the resurgence of Qakbot malware mere months after the FBI and other law enforcement agencies shuttered the Windows botnet.…

☐ β˜† βœ‡ The Register - Security

Hacktivists boast: We shut down Iran's gas pumps today

December 18th 2023 at 22:45

Predatory Sparrow previously knocked out railways and a steel plant

Hacktivists reportedly disrupted services at about 70 percent of Iran's gas stations in a politically motivated cyberattack.…

☐ β˜† βœ‡ The Register - Security

Mr Cooper cyberattack laid bare: 14.7M people's info stolen, costs hit $25M

December 18th 2023 at 20:54

Mortgage lender says no evidence of identity theft (yet) after SSNs, DoBs, addresses, more swiped

Mortgage lender Mr Cooper has now admitted almost 14.7 million people's private information, including addresses and bank account numbers, were stolen in an earlier IT security breach, which is expected to cost the business at least $25 million to clean up.…

☐ β˜† βœ‡ The Register - Security

Cyber-crooks slip into Vans, trample over operations

December 18th 2023 at 19:45

IT systems encrypted, personal data pilfered from North Face parent, we're told

A digital break-in has disrupted VF Corp's operations and its ability to fulfill orders, according to the apparel and footwear giant.…

☐ β˜† βœ‡ The Register - Security

National Grid latest UK org to zap Chinese kit from critical infrastructure

December 18th 2023 at 12:36

Move reportedly made after consulting with National Cyber Security Centre

The National Grid is reportedly the latest organization in the UK to begin pulling China-manufactured equipment from its network over cybersecurity fears.…

☐ β˜† βœ‡ The Register - Security

MongoDB warns breach of internal systems exposed customer contact info

December 18th 2023 at 02:25

PLUS: Cancer patients get ransom notes for Christmas, Delta Dental is the latest MOVEit victim, and critical vulns

Infosec in brief MongoDB on Saturday issued an alert warning of "a security incident involving unauthorized access to certain MongoDB corporate systems, which includes exposure of customer account metadata and contact information."…

☐ β˜† βœ‡ The Register - Security

Pro-China campaign targeted YouTube with AI avatars

December 18th 2023 at 01:06

PLUS: Beijing wants ten-minute reporting of infosec incidents; Infosys CFO bails; TikTok's Indonesia comeback approved, for now

Asia In Brief Think tank Australian Strategic Policy Institute (ASPI) last week published details of a campaign that spreads English language pro-China and anti-US narratives on YouTube.…

☐ β˜† βœ‡ The Register - Security

Hundreds of thousands of dollars in crypto stolen after Ledger code poisoned

December 16th 2023 at 00:13

Former worker phished then NPM repo hijacked

Cryptocurrency wallet maker Ledger says someone slipped malicious code into one of its JavaScript libraries to steal more than half a million dollars from victims.…

☐ β˜† βœ‡ The Register - Security

Kraft Heinz suggests we simmer down about Snatch ransomware attack claims

December 15th 2023 at 19:59

Ah, beans

The Kraft Heinz Company says its systems are all up and running as usual as it probes claims that some of its data was stolen by ransomware crooks.…

☐ β˜† βœ‡ The Register - Security

NKabuse backdoor harnesses blockchain brawn to hit several architectures

December 15th 2023 at 14:28

Novel malware adapts delivers DDoS attacks and provides RAT functionality

Incident responders say they've found a new type of multi-platform malware abusing the New Kind of Network (NKN) protocol.…

☐ β˜† βœ‡ The Register - Security

To BCC or not to BCC – that is the question data watchdog wants answered

December 15th 2023 at 09:59

The dos and don'ts of bulk emailing

A data regulator has reminded companies they need to take care while writing emails to avoid unintentionally blurting out personal data.…

☐ β˜† βœ‡ The Register - Security

Microsoft seizes websites used to sell phony email accounts to Scattered Spider and other crims

December 14th 2023 at 21:54

That should solve the global cybercrime problem, right?

Microsoft has taken down US-based infrastructure and websites used by a cybercrime group to sell fraudulent online accounts to other crooks including Scattered Spider, the infamous social-engineering and extortion crew that hacked two Las Vegas casinos over the summer.…

☐ β˜† βœ‡ The Register - Security

Russia joins North Korea in sending state-sponsored cyber troops to pick on TeamCity users

December 14th 2023 at 14:12

National security and infosec authorities band together to help victims sniff out stealthy Russian baddies hiding in networks

Updated The offensive cyber unit linked to Russia's Foreign Intelligence Service (SVR) is exploiting the critical vulnerability affecting the JetBrains TeamCity CI/CD server at scale, and has been since September, authorities warn.…

☐ β˜† βœ‡ The Register - Security

Money-grubbing crooks abuse OAuth – and baffling absence of MFA – to do financial crimes

December 14th 2023 at 11:03

Business email compromise, illicit cryptomining, phishing ... if it makes a dollar, this lot do it

Multiple miscreants are misusing OAuth to automate financially motivated cyber crimes – such as business email compromise (BEC), phishing, large-scale spamming campaigns – and deploying virtual machines to illicitly mine for cryptocurrencies, according to Microsoft.…

☐ β˜† βœ‡ The Register - Security

Surprise! Email from personal. <br> information.reveal@gmail.com is not going to contain good news

December 14th 2023 at 09:55

Internet plod highlight tactics used by cruel Karakurt crime gang

Karakurt, a particularly nasty extortion gang that uses "extensive harassment" to pressure victims into handing over millions of dollars in ransom payments after compromising their IT infrastructure, pose a "significant challenge" for network defenders, we're told.…

☐ β˜† βœ‡ The Register - Security

The SANS Holiday Hack Challenge is back!

December 14th 2023 at 09:07

Skip the sleigh and sail with Santa in this year’s fun, hands-on SANS cybersecurity event

Sponsored Post Whether you are considering a career in cyber security or you already work in the industry, the 2023 SANS Holiday Hack Challenge is a great way of combining festive fun and learning. Who knows, the skills you acquire this holiday season might even help you foil a nefarious hacker at Yuletide next year.…

☐ β˜† βœ‡ The Register - Security

Learning the safety language of the cloud

December 13th 2023 at 14:19

Protecting your cloud from cyber security threats starts by understanding what it’s telling you

Webinar In China, clouds are a symbol of luck. See multiple layering of clouds in a blue sky can mean you are in line to receive eternal happiness.…

☐ β˜† βœ‡ The Register - Security

Nearly a million non-profit donors' details left exposed in unsecured database

December 13th 2023 at 10:30

Trusted by major charities, DonorView publicly exposed children’s names and addresses, among other data

Close to a million records containing personally identifiable information belonging to donors that sent money to non-profits were found exposed in an online database.…

☐ β˜† βœ‡ The Register - Security

Cyber security isn’t simple, but it could be

December 13th 2023 at 08:59

The biggest problem is a tendency to ignore problems you can’t see or haven’t looked for, says SecurityHQ

Sponsored Feature Most experts agree cybersecurity is now so complex that managing it has become a security problem in itself.…

☐ β˜† βœ‡ The Register - Security

Think tank report labels NSO, Lazarus as 'cyber mercenaries'

December 13th 2023 at 06:05

Sure, they do crimes. But the plausible deniability governments adore means they deserve a different label

Cybercrime gangs like the notorious Lazarus group and spyware vendors like Israel's NSO should be considered cyber mercenaries – and become the subject of a concerted international response – according to a Monday report from Delhi-based think tank Observer Research Foundation (ORF).…

☐ β˜† βœ‡ The Register - Security

Final Patch Tuesday of 2023 goes out with a bang

December 13th 2023 at 00:41

Microsoft fixed 36 flaws. Adobe addressed 212. Apple, Google, Cisco, VMware and Atlassian joined the party

It's the last Patch Tuesday of 2023, which calls for celebration – just as soon as you update Windows, Adobe, Google, Cisco, FortiGuard, SAP, VMware, Atlassian and Apple products, of course.…

☐ β˜† βœ‡ The Register - Security

Cloud engineer wreaks havoc on bank network after getting fired

December 12th 2023 at 19:43

Now he's got two years behind bars to think about his bad choices

An ex-First Republic Bank cloud engineer was sentenced to two years in prison for causing more than $220,000 in damage to his former employer's computer network after allegedly using his company-issued laptop to watch pornography.…

☐ β˜† βœ‡ The Register - Security

Discord in the ranks: Lone Airman behind top-secret info leak on chat platform

December 12th 2023 at 18:00

Poor cybersecurity hygiene in the military? Surely not!

There was only one US Air National Guardsman behind the leak of top-secret US military documents on Discord, but his chain of command bears some responsibility for letting it happen on their watch.…

☐ β˜† βœ‡ The Register - Security

Northern Ireland cops count human cost of August data breach

December 12th 2023 at 13:46

Officers potentially targeted by dissidents can't afford to relocate for their safety, while others seek support to change their names

An official review of the Police Service of Northern Ireland's (PSNI) August data breach has revealed the full extent of the impact on staff.…

☐ β˜† βœ‡ The Register - Security

BlackBerry squashes plan to spin out its IoT biz

December 12th 2023 at 08:23

Board and incoming CEO decide reorganizing is better than splitting

BlackBerry has decided its plan to split into two separate companies is not a good idea and will instead reorganize itself into two independent divisions.…

☐ β˜† βœ‡ The Register - Security

Interpol moves against human traffickers who enslave people to scam you online

December 12th 2023 at 06:30

Scum lure folks with promises of good jobs in crypto and then won't let them leave

Hundreds of suspected people smugglers have been arrested, and 163 potential victims rescued from servitude, as part of an Interpol-coordinated operation dubbed "Turquesa V" that targeted cyber criminals who lure workers into servitude to carry out their scams.…

☐ β˜† βœ‡ The Register - Security

Proposed US surveillance regime would enlist more businesses

December 12th 2023 at 01:45

Expanded service provider definition could force cafes and hotels to spy for the feds

Many US businesses may be required to assist in government-directed surveillance – depending upon which of two reform bills before Congress is approved.…

☐ β˜† βœ‡ The Register - Security

2.5M patients infected with data loss in Norton Healthcare ransomware outbreak

December 11th 2023 at 20:01

AlphV lays claims to the intrusion

Norton Healthcare, which runs eight hospitals and more than 30 clinics in Kentucky and Indiana, has admitted crooks may have stolen 2.5 million people's most sensitive data during a ransomware attack in May.…

☐ β˜† βœ‡ The Register - Security

Memory-safe languages so hot right now, agrees Lazarus Group as it slings DLang malware

December 11th 2023 at 18:08

Latest offensive cyber group to switch to atypical programming for payloads

Research into Lazarus Group's attacks using Log4Shell has revealed novel malware strains written in an atypical programming language.…

☐ β˜† βœ‡ The Register - Security

Two years on, 1 in 4 apps still vulnerable to Log4Shell

December 11th 2023 at 15:01

Lack of awareness still blamed for patching apathy despite it being among most infamous bugs of all time

Two years after the Log4Shell vulnerability in the open source Java-based Log4j logging utility was disclosed, circa one in four applications are dependent on outdated libraries, leaving them open to exploitation.…

☐ β˜† βœ‡ The Register - Security

Read the clouds, reduce the cyber risk

December 11th 2023 at 13:52

Why a one-size- fits- all approach to cloud security is unlikely to work in multi-cloud deployments

Webinar In the natural world, there are ten different kinds of cloud - a rare simplicity in meteorological terms. But in our global business environment, there's no single defining feature to aid classification.…

☐ β˜† βœ‡ The Register - Security

23andMe responds to breach with new suit-limiting user terms

December 11th 2023 at 11:46

Also: 'well-known Bay Area tech' firm's laptops stolen and check out some critical vulns

Security in brief The saga of 23andMe's mega data breach has reached something of a conclusion, with the company saying its probe has determined millions of leaked records originated from illicit break-ins into just 14,000 accounts.…

☐ β˜† βœ‡ The Register - Security

VictoriaMetrics takes organic growth over investor pressure

December 11th 2023 at 10:15

Keeping the lights on with an enterprise product while staying true to your roots

Interview Monitoring biz VictoriaMetrics is relatively unusual in its field. It is yet to accept external investment, preferring instead to try to grow organically rather than being forced to through a private equity meat grinder by committing to grow by X every year until the investor exits.…

☐ β˜† βœ‡ The Register - Security

Hollywood plays unwitting Cameo in Kremlin plot to discredit Zelensky

December 9th 2023 at 11:28

Microsoft spots surge in pro-Russia exploits of video platform to spread propaganda

An unknown pro-Russia influence group spent time recruiting unwitting Hollywood actors to assist in smear campaigns against Ukraine and its president Volodymyr Zelensky.…

☐ β˜† βœ‡ The Register - Security

Competing Section 702 surveillance bills on collision path for US House floor

December 8th 2023 at 22:30

End-of-year deadline looms on US surveillance

Two competing bills to reauthorize America's FISA Section 702 spying powers advanced in the House of Representatives committees this week, setting up Congress for a battle over warrantless surveillance before the law lapses in the New Year.…

☐ β˜† βœ‡ The Register - Security

That call center tech scammer could be a human trafficking victim

December 8th 2023 at 15:25

Interpol increasingly concerned as abject abuse of victims scales far beyond Asia origins

Human trafficking for the purposes of populating cyber scam call centers is expanding beyond southeast Asia, where the crime was previously isolated.…

☐ β˜† βœ‡ The Register - Security

Polish train maker denies claims its software bricked rolling stock maintained by competitor

December 8th 2023 at 06:30

Says it was probably hacked, which isn't good news either

A trio of Polish security researchers claim to have found that trains built by Newag SA contain software that sabotages them if the hardware is serviced by competitors.…

☐ β˜† βœ‡ The Register - Security

Five Eyes nations warn Moscow's mates at the Star Blizzard gang have new phishing targets

December 8th 2023 at 01:31

The Russians are coming! Err, they've already infiltrated UK, US inboxes

Russia-backed attackers have named new targets for their ongoing phishing campaigns, with defense-industrial firms and energy facilities now in their sights, according to agencies of the Five Eyes alliance.…

☐ β˜† βœ‡ The Register - Security

Attacks abuse Microsoft DHCP to spoof DNS records and steal secrets

December 7th 2023 at 22:11

Akamai says it reported the flaws to Microsoft. Redmond shrugged

A series of attacks against Microsoft Active Directory domains could allow miscreants to spoof DNS records, compromise Active Directory and steal all the secrets it stores, according to Akamai security researchers.…

☐ β˜† βœ‡ The Register - Security

US and EU infosec authorities pen intel-sharing pact

December 7th 2023 at 18:28

As Cyber Solidarity Act edges closer to full adoption in Europe

The US Cybersecurity and Infrastructure Security Agency (CISA) has signed a working arrangement with its EU counterparts to increase cross-border information sharing and more to tackle criminals.…

☐ β˜† βœ‡ The Register - Security

Belgian man charged with smuggling sanctioned military tech to Russia and China

December 7th 2023 at 07:30

Indictments allege plot to shift FPGAs, accelerometers, and spycams

A Belgian man has been arrested and charged for his role in a years-long smuggling scheme to export military-grade electronics from the US to Russia and China.…

❌