FreshRSS

πŸ”’
☐ β˜† βœ‡ The Register - Security

Stanford University failed to detect ransomware intruders for 4 months

March 13th 2024 at 12:05

27,000 individuals had data stolen, which for some included names and social security numbers

Stanford University says the cybersecurity incident it dealt with last year was indeed ransomware, which it failed to spot for more than four months.…

☐ β˜† βœ‡ The Register - Security

Reducing the cloud security overhead

March 13th 2024 at 08:51

Why creating a layered defensive strategy that includes security by design can help address cloud challenges

Sponsored Feature The world is filled with choices. Whether it's the 20 different types of shampoo on offer at the grocery store, or the dozens of Linux distros you can try for free, you can have it all.…

☐ β˜† βœ‡ The Register - Security

Whizkids jimmy OpenAI, Google's closed models

March 13th 2024 at 08:34

Infosec folk aren’t thrilled that if you poke APIs enough, you learn AI's secrets

Boffins have managed to pry open closed AI services from OpenAI and Google with an attack that recovers an otherwise hidden portion of transformer models.…

☐ β˜† βœ‡ The Register - Security

March Patch Tuesday sees Hyper-V join the guest-host escape club

March 13th 2024 at 00:16

Critical bugs galore among 61 Microsoft fixes, 56 from Adobe, a dozen from SAP, and a fistful from Fortinet

Patch Tuesday Microsoft's monthly patch drop has arrived, delivering a mere 61 CVE-tagged vulnerabilities – none listed as under active attack or already known to the public.…

☐ β˜† βœ‡ The Register - Security

Meta sues ex infra VP for allegedly stealing top-secret datacenter blueprints

March 12th 2024 at 22:39

Exec accused of using own work PC to swipe confidential AI and staffing docs for stealth cloud startup

An ex-Meta veep has been sued by his former bosses for "brazenly disloyal and dishonest conduct" – and by that, they mean he allegedly stole confidential documents to help him build and recruit colleagues for an AI cloud startup. …

☐ β˜† βœ‡ The Register - Security

Biden's budget proposal boosts CISA funding to $3B

March 12th 2024 at 18:30

Plus almost $1.5b for health-care cybersecurity

US President Joe Biden has asked Congress to approve an extra $103 million in funding for the Cybersecurity and Infrastructure Security Agency, bringing CISA's total budget to $3 billion.…

☐ β˜† βœ‡ The Register - Security

JetBrains is still mad at Rapid7 for the ransomware attacks on its customers

March 12th 2024 at 16:30

War of words wages on between vendors divided

Last week, we wrote about how security outfit Rapid7 threw JetBrains, the company behind the popular CI/CD platform TeamCity, under the bus over allegations of silent patching. Now, JetBrains has gone on the offensive.…

☐ β˜† βœ‡ The Register - Security

UK council yanks IT systems and phone lines offline following cyber ambush

March 12th 2024 at 11:45

Targeting recovery this week, officials still trying to 'dentify the nature of the incident'

Leicester City Council says IT systems and a number of its critical service phone lines will remain down until later this week at the earliest following a "cyber incident".…

☐ β˜† βœ‡ The Register - Security

French government sites disrupted by très grande DDoS

March 12th 2024 at 06:26

Russia and Sudan top the list of suspects

Several French government websites have been disrupted by a severe distributed denial of service attack.…

☐ β˜† βœ‡ The Register - Security

White House and lawmakers increase pressure on UnitedHealth to ease providers' pain

March 12th 2024 at 00:02

US senator calls cyber attack 'inexcusable,' calls for mandatory security rules

The Biden administration and US lawmakers are turning up the pressure on UnitedHealth group to ease medical providers' pain after the ransomware attack on Change Healthcare, by expediting payments to hospitals, physicians and pharmacists – among other tactics.…

☐ β˜† βœ‡ The Register - Security

Kremlin accuses America of plotting cyberattack on Russian voting systems

March 11th 2024 at 21:58

Don't worry, we have a strong suspicion Putin's still gonna win

The Kremlin has accused the United States of meddling in Russia's upcoming presidential election, and even accused Uncle Sam of planning a cyberattack on the country's online voting system.…

☐ β˜† βœ‡ The Register - Security

British Library pushes the cloud button, says legacy IT estate cause of hefty rebuild

March 11th 2024 at 13:30

Five months in and the mammoth post-ransomware recovery has barely begun

The British Library says legacy IT is the overwhelming factor delaying efforts to recover from the Rhysida ransomware attack in late 2023.…

☐ β˜† βœ‡ The Register - Security

How do you lot feel about Pay or say OK to ads model, asks ICO

March 11th 2024 at 11:16

And does it count as consent?

The UK's Information Commissioner's Office (ICO) has opened a consultation on "consent or pay" business models. We're sure readers of The Register will have a fair few things to say.…

☐ β˜† βœ‡ The Register - Security

Microsoft waited 6 months to patch actively exploited admin-to-kernel vulnerability

March 11th 2024 at 04:28

PLUS: NSA shares cloud security tips; Infosec training for Jordanian women; Critical vulnerabilities

Infosec in brief Cybersecurity researchers informed Microsoft that Notorious North Korean hackers Lazarus Group discovered the "holy grail" of rootkit vulnerabilities in Windows last year, but Redmond still took six months to patch the problem.…

☐ β˜† βœ‡ The Register - Security

Cybercrime crew Magnet Goblin bursts onto the scene exploiting Ivanti holes

March 8th 2024 at 22:55

Plus: CISA pulls plug on couple of systems feared compromised

There's yet another group of miscreants out there hijacking insecure Ivanti devices: A new, financially motivated gang dubbed Magnet Goblin has emerged from the shadowy digital depths with a knack for rapidly exploiting newly disclosed vulnerabilities before vendors have issued a fix.…

☐ β˜† βœ‡ The Register - Security

Microsoft confirms Russian spies stole source code, accessed internal systems

March 8th 2024 at 16:56

Still 'no evidence' of any compromised customer-facing systems, we're told

Microsoft has now confirmed that the Russian cyberspies who broke into its executives' email accounts stole source code and gained access to internal systems. The Redmond giant also characterized the intrusion as "ongoing."…

☐ β˜† βœ‡ The Register - Security

Change Healthcare registers pulse after crippling ransomware attack

March 8th 2024 at 14:33

Remaining services are expected to return in the coming weeks after $22M ALPHV ransom

Change Healthcare has taken the first steps toward a full recovery from the ransomware attack in February by bringing its electronic prescription services back online.…

☐ β˜† βœ‡ The Register - Security

Chrome users – get an alert when extensions are in danger of falling into wrong hands

March 7th 2024 at 19:45

Under New Management is an early-warning system for potential poisoning of add-ons with malware

Millions of Chrome users now have a way to guard against the threat of extension subversion, that is, if they don't mind installing yet another browser extension.…

☐ β˜† βœ‡ The Register - Security

Swiss cheese security? Play ransomware gang milks government of 65,000 files

March 8th 2024 at 12:35

Classified docs, readable passwords, and thousands of personal information nabbed in Xplain breach

The Swiss government had around 65,000 files related to it stolen by the Play ransomware gang during an attack on an IT supplier, its National Cyber Security Center (NCSC) says.…

☐ β˜† βœ‡ The Register - Security

Font security 'still a Helvetica of a problem' says Australian graphics outfit Canva

March 8th 2024 at 03:57

Who knew that unzipping a font archive could unleash a malicious file

Online graphic design platform Canva went looking for security problems in fonts, and found three – in "strange places."…

☐ β˜† βœ‡ The Register - Security

Securing open source software: Whose job is it, anyway?

March 8th 2024 at 01:02

CISA announces more help, and calls on app makers to step up

The US government and some of the largest open source foundations and package repositories have announced a series of initiatives intended to improve software supply-chain security, while also repeating calls for developers to increase support for such efforts.…

☐ β˜† βœ‡ The Register - Security

We're not Meta support: State AGs tell Zuck to fix rampant account takeover problem

March 7th 2024 at 21:45

'We refuse to operate as customer service representatives'

A group of 41 US state attorneys general, tired of serving as a customer complaint clearinghouse for Facebook and Instagram users, have sent a letter to Meta asking it to figure out how to reduce a "dramatic and persistent spike" in account takeovers.…

☐ β˜† βœ‡ The Register - Security

Possible China link to Change Healthcare ransomware attack

March 7th 2024 at 18:30

Alleged crim bought SmartScreen Killer, Cobalt Strike on dark-web markets

A criminal claiming to be an ALPHV/BlackCat affiliate β€” the gang responsible for the widely disruptive Change Healthcare ransomware infection last month β€”Β  may have ties to Chinese government-backed cybercrime syndicates.…

☐ β˜† βœ‡ The Register - Security

JetBrains TeamCity under attack by ransomware thugs after disclosure mess

March 7th 2024 at 16:34

More than 1,000 servers remain unpatched and vulnerable

Security researchers are increasingly seeing active exploit attempts using the latest vulnerabilities in JetBrains' TeamCity that in some cases are leading to ransomware deployment.…

☐ β˜† βœ‡ The Register - Security

Belgian ale legend Duvel's brewery borked as ransomware halts production

March 7th 2024 at 12:45

Biz reassures quaffers it has enough beer, expects quick recovery before weekend

Belgian beer brewer Duvel says a ransomware attack has brought its facility to a standstill while its IT team works to remediate the damage.…

☐ β˜† βœ‡ The Register - Security

VMware urges emergency action to blunt hypervisor flaws

March 7th 2024 at 07:30

Critical vulns in USB under ESXi and desktop hypervisors found by Chinese researchers at cracking contest

Hypervisors are supposed to provide an inviolable isolation layer between virtual machines and hardware. But hypervisor heavyweight VMware by Broadcom yesterday revealed its hypervisors are not quite so inviolable as it might like.…

☐ β˜† βœ‡ The Register - Security

Reminder: Infostealer malware is coming for your ChatGPT credentials

March 7th 2024 at 06:27

Singaporean researchers note rising presence of OpenAI logins in infostealer malware logs

Stolen ChatGPT credentials are a hot commodity on the dark web, according to Singapore-based threat intelligence firm Group-IB, which claims to have found some 225,000 log files containing login details for the service last year.…

☐ β˜† βœ‡ The Register - Security

US politicians want ByteDance to sell off TikTok or face ban

March 7th 2024 at 06:05

The American mind must not be at the mercy of Chinese algorithms

A group of US lawmakers introduced legislation on Tuesday that, if passed, would force Chinese internet concern ByteDance to divest TikTok – its most valuable property – or see it banned in the US.…

☐ β˜† βœ‡ The Register - Security

Lawsuit claims gift card fraud is the gift that keeps on giving, to Google

March 7th 2024 at 01:15

Play Store commissions are a nice little earner, wherever they come from

Google has been accused of profiting from gift card scams.…

☐ β˜† βœ‡ The Register - Security

Chinese chap charged with stealing Google’s AI datacenter secrets

March 7th 2024 at 00:37

Moonlighted for PRC companies after side-stepping Big G's security, allegedly

A now-former Google employee has been charged with stealing the ad giant’s AI trade secrets while quietly working for two Chinese companies – after easily defeating whatever security controls Big G had in place.…

☐ β˜† βœ‡ The Register - Security

FBI: Critical infrastructure suffers spike in ransomware attacks

March 6th 2024 at 20:49

Jump in overall cybercrime reports, $60M-plus reportedly lost to extortionists alone, Feds reckon

Digital crimes potentially cost victims more than $12.5 billion last year, according to the FBI's latest Internet Crime Complaint Center (IC3) annual report. …

☐ β˜† βœ‡ The Register - Security

Apple's trademark tight lips extend to new iPhone, iPad zero-days

March 6th 2024 at 17:01

Two flaws fixed, one knee bent to the EU, and a budding cybersecurity star feature in iOS 17.4

Apple's latest security patches address four vulnerabilities affecting iOS and iPadOS, including two zero-days that intel suggests attackers have already exploited.…

☐ β˜† βœ‡ The Register - Security

Capita says 2023 cyberattack costs a factor as it reports staggering Β£100M+ loss

March 6th 2024 at 12:31

Additional cuts announced, sparking fears of further layoffs

Outsourcing giant Capita today reported a net loss of Β£106.6 million ($135.6 million) for calendar 2023, with the costly cyberattack by criminals making a hefty dent in its annual financials.…

☐ β˜† βœ‡ The Register - Security

Chip lobby group SEMI to EU: Export restrictions should only be used in self-defense

March 6th 2024 at 08:23

Please don't scare away foreign investors - who do you think pays for this stuff?

SEMI, an industry association representing 3,000 chip vendors, would really appreciate it if the European Union would back off plans to impose export controls on China, arguing that they should only be used as a "last resort" to protect national security.…

☐ β˜† βœ‡ The Register - Security

Japan orders local giants LINE and NAVER to disentangle their tech stacks

March 6th 2024 at 03:29

Government mighty displeased about a shared Active Directory that led to a big data leak

Japan's government has ordered local tech giants LINE and NAVER to disentangle their tech stacks, after a data breach saw over 510,000 users' data exposed.…

☐ β˜† βœ‡ The Register - Security

Uncle Sam intervenes as Change Healthcare ransomware fiasco creates mayhem

March 6th 2024 at 00:30

As the crooks behind the attack - probably ALPHV/BlackCat - fake their own demise

The US government has stepped in to help hospitals and other healthcare providers affected by the Change Healthcare ransomware infection, offering more relaxed Medicare rules and urging advanced funding to providers.…

☐ β˜† βœ‡ The Register - Security

Fidelity customers' financial info feared stolen in suspected ransomware attack

March 5th 2024 at 19:28

Insurance giant blames Infosys, LockBit claims credit

Criminals have probably stolen nearly 30,000 Fidelity Investments Life Insurance customers' personal and financial information β€” including bank account and routing numbers, credit card numbers and security or access codes β€” after breaking into Infosys' IT systems in the fall.…

☐ β˜† βœ‡ The Register - Security

US accuses Army vet cyber-Casanova of sharing Russia-Ukraine war secrets

March 5th 2024 at 17:06

Where better to expose confidential data than on a dating app?

Yet another US military man is facing a potentially significant stretch in prison after allegedly sending secret national defense information (NDI) overseas.…

☐ β˜† βœ‡ The Register - Security

IP address X-posure now a feature on Musk's social media thing

March 5th 2024 at 16:18

Just a little FYI

Video and audio calling features for X Premium users added last year to Elon Musk's version of Twitter have been expanded to everyone on the platform, and FYI: It may reveal your IP address to those you're nattering away to.…

☐ β˜† βœ‡ The Register - Security

Rapid7 throws JetBrains under the bus for 'uncoordinated vulnerability disclosure'

March 5th 2024 at 13:15

Exploits began within hours of the original disclosure, so patch now

Updated Security shop Rapid7 is criticizing JetBrains for flouting its policy against silent patching regarding fixes for two fresh vulnerabilities in the TeamCity CI/CD server.…

☐ β˜† βœ‡ The Register - Security

Spam crusade lands charity in hot water with data watchdog

March 5th 2024 at 09:30

Penny Appeal sent more than 460,000 texts asking for money to help war-torn countries, no opt out

Typically it is energy improvement peddlers or debt help specialists that are disgraced by Britain's data watchdog for spamming unsuspecting households, but the latest entrant in the hall of shame is a charity.…

☐ β˜† βœ‡ The Register - Security

Cloudflare wants to put a firewall in front of your LLM

March 5th 2024 at 01:32

Claims to protect against DDoS, sensitive data leakage

Cloudflare has tweaked its web application firewall (WAF) to add protections for applications using large language models.…

☐ β˜† βœ‡ The Register - Security

American Express admits card data exposed and blames third party

March 4th 2024 at 23:04

Don't leave home without … IT security

A security failure at a third-party vendor exposed an untold number of American Express card numbers, expiry dates, and other data to persons unknown.…

☐ β˜† βœ‡ The Register - Security

Change Healthcare attack latest: ALPHV bags $22M in Bitcoin amid affiliate drama

March 4th 2024 at 21:01

No honor among thieves?

ALPHV/BlackCat, the gang behind the Change Healthcare cyberattack, has received more than $22 million in Bitcoin in what might be a ransomware payment.…

☐ β˜† βœ‡ The Register - Security

Seoul accuses North Korea of stealing southern chipmakers' designs

March 4th 2024 at 20:00

Kim Jong Un's all in for home-built silicon says warning

North Korean government spies have broken into the servers of at least two chipmakers and stolen product designs as part of attempts to spur Kim Jong Un's plans for a domestic semiconductor industry, according to Seoul's security agency.…

☐ β˜† βœ‡ The Register - Security

German defense chat overheard by Russian eavesdroppers on Cisco's WebEx

March 4th 2024 at 17:45

Officials can't tell whether the tape was edited, but fear Kremlin has more juicy bits to release in the future

The German Ministry of Defense (Bundeswehr) has confirmed that a recording of a call between high-ranking officials discussing war efforts in Ukraine, leaked by Russian media, is legitimate.…

☐ β˜† βœ‡ The Register - Security

Ransomware ban backers insist thugs must be cut off from payday

March 4th 2024 at 14:30

Increasingly clear number of permanent solutions is narrowing

Global law enforcement authorities' attempts to shutter the LockBit ransomware crew have sparked a fresh call for a ban on ransomware payments to perpetrators.…

☐ β˜† βœ‡ The Register - Security

The federal bureau of trolling hits LockBit, but the joke's on us

March 4th 2024 at 09:30

When you can't lock 'em up, lock 'em out

Opinion The best cop shows excel at mind games: who's tricking whom, who really wins, and what price they pay. A twist of humor adds to the drama and keeps us hooked. It's rare enough in real life, far less so in the grim meat grinder of cybersecurity, yet sometimes it happens. It's happening right now.…

☐ β˜† βœ‡ The Register - Security

LockBit's contested claim of fresh ransom payment suggests it's been well hobbled

March 4th 2024 at 03:15

ALSO: CISA warns Ivanti vuln mitigations might not work, SAML hijack doesn't need ADFS, and crit vulns

Infosec in brief The infamous LockBit ransomware gang has been busy in the ten days since an international law enforcement operation took down many of its systems. But despite its posturing, the gang might have suffered more than it's letting on.…

☐ β˜† βœ‡ The Register - Security

Ahead of Super Tuesday, US elections face existential and homegrown threats

March 4th 2024 at 01:15

Misinformation is rife, AI makes it easier to create, and 42 percent of the planet’s inhabitants get to vote this year

Feature Two US intelligence bigwigs last week issued stark warnings about foreign threats to American election integrity and security – and the nation's ability to counter these adversaries.…

☐ β˜† βœ‡ The Register - Security

Air National Guardsman Teixeira to admit he was Pentagon files leaker

March 1st 2024 at 22:03

Turns out bragging on Discord has unfortunate consequences

Updated Jack Teixeira, the Air National Guardsman accused of leaking dozens of classified Pentagon documents, is expected to plead guilty in a US court on Monday.…

☐ β˜† βœ‡ The Register - Security

Judge orders NSO to cough up Pegasus super-spyware source code

March 1st 2024 at 21:34

/* Hope no one ever reads these functions lmao */

NSO Group, the Israel-based maker of super-charged snoopware Pegasus, has been ordered by a federal judge in California to share the source code for "all relevant spyware" with Meta's WhatsApp.…

☐ β˜† βœ‡ The Register - Security

Iranian charged over attacks against US defense contractors, government agencies

March 1st 2024 at 18:30

$10M bounty for anyone with info leading to Alireza Shafie Nasab's identification or location

The US Department of Justice has unsealed an indictment accusing an Iranian national of a years-long campaign that compromised hundreds of thousands of accounts and attempting to infiltrate US defense contractors and multiple government agencies.…

☐ β˜† βœ‡ The Register - Security

In the vanguard of 21st century cyber threats

March 1st 2024 at 16:00

Everything you need to know about quantum safe encryption

Webinar The quantum threat might seem futuristic, more like something you'd encounter in a science fiction film. But it's arguably already a danger to real cyber security defences.…

☐ β˜† βœ‡ The Register - Security

Cops visit school of 'wrong person's child,' mix up victims and suspects in epic data fail

March 1st 2024 at 12:40

Data watchdog reprimands police force for confusing 2 people with same name and birthday to disastrous results

The UK's Information Commissioner's Office has put the West Midlands Police (WMP) on the naughty step after the force was found to have repeatedly mixed up two people's personal data for years.…

☐ β˜† βœ‡ The Register - Security

Keeping one step ahead of cyber security threats

March 1st 2024 at 09:05

How zero trust controls and Google AI can strengthen your organization’s defences

Webinar Dealing with cyber security incidents is an expensive business. Each data breach costs an estimated $4.35 million on average and it's not as if the volume of cyber attacks is falling - last year, they rose by 38 percent according to Google Cloud.…

☐ β˜† βœ‡ The Register - Security

NTT boss takes early retirement to atone for data leak

March 1st 2024 at 05:27

No mere mea culpa would suffice after 9.2 million records leaked over a decade, warnings were ignored, and lies were told

NTT West president Masaaki Moribayashi announced his resignation on Thursday, effective at the end of March, in atonement for the leak of data pertaining to 9.28 million customers that came to light last October.…

☐ β˜† βœ‡ The Register - Security

GitHub struggles to keep up with automated malicious forks

March 1st 2024 at 00:45

Cloned then compromised, bad repos are forked faster than they can be removed

A malware distribution campaign that began last May with a handful of malicious software packages uploaded to the Python Package Index (PyPI) has spread to GitHub and expanded to reach at least 100,000 compromised repositories.…

☐ β˜† βœ‡ The Register - Security

Turns out cops are super interested in subpoenaing suspects' push notifications

February 29th 2024 at 22:30

Those little popups may reveal location, device details, IP address, and more

More than 130 petitions seeking access to push notification metadata have been filed in US courts, according to a Washington Post investigation – a finding that underscores the lack of privacy protection available to users of mobile devices.…

☐ β˜† βœ‡ The Register - Security

White House goes to court, not Congress, to renew warrantless spy powers

February 29th 2024 at 21:44

Choose your own FISA Section 702 adventure: End-run around lawmakers or business as usual?

The Biden Administration has asked a court, rather than Congress, to renew controversial warrantless surveillance powers used by American intelligence and due to expire within weeks. It's a move that is either business as usual or an end-run around spying reforms, depending on who in Washington you believe.…

❌