FreshRSS

πŸ”’
☐ β˜† βœ‡ The Register - Security

FTC goes undercover to probe suspected antivirus scam, scores $26M settlement

March 14th 2024 at 20:24

Imagine trying to trick folks into buying $500 of unnecessary repairs – and they turn out to be federal agents

A pair of tech support businesses accused of swindling marks out of their hard-earned cash have agreed to cough up a $26 million settlement following an undercover probe by the FTC.…

☐ β˜† βœ‡ The Register - Security

LockBit ransomware kingpin gets 4 years behind bars

March 14th 2024 at 18:26

Canadian-Russian said to have turned to a life of cybercrime during pandemic, now must pay the price – literally

A LockBit ransomware kingpin has been sentenced to almost four years behind bars and ordered to pay more than CA$860,000 ($635,000, Β£500,000) in restitution to some of his victims by a Canadian court as he awaits extradition to the US.…

☐ β˜† βœ‡ The Register - Security

Google gooses Safe Browsing with real-time protection that doesn't leak to ad giant

March 14th 2024 at 17:58

Rare occasion when you do want Big Tech to make a hash of it

Google has enhanced its Safe Browsing service to enable real-time protection in Chrome for desktop, iOS, and soon Android against risky websites, without sending browsing history data to the ad biz.…

☐ β˜† βœ‡ The Register - Security

Record breach of French government exposes up to 43 million people's data

March 14th 2024 at 16:06

Zut alors! Department for registering and helping unemployed people broken into

A French government department - responsible for registering and assisting unemployed people - is the latest victim of a mega data breach that compromised the information of up to 43 million citizens.…

☐ β˜† βœ‡ The Register - Security

International effort to disrupt cybercrime moves into operational phase

March 14th 2024 at 15:00

Will the WEF experiment work?

The Cybercrime Atlas, a massive undertaking that aims to disrupt cybercriminals across the globe, enters its operational phase in 2024, two years after organizers laid the groundwork at the RSA Conference.…

☐ β˜† βœ‡ The Register - Security

US to probe Change Healthcare's data protection standards as lawsuits mount

March 14th 2024 at 14:03

Services slowly coming back online but providers still struggling

Change Healthcare is being investigated over the alleged 6 TB data theft by the ALPHV ransomware group as it continues recovery efforts.…

☐ β˜† βœ‡ The Register - Security

US Congress goes bang, bang, on TikTok sale-or-ban plan

March 14th 2024 at 01:46

Bill proposes to do to China what China already does to the US – make life hard for foreign social networks

The United States House of Representatives on Wednesday passed the Protecting Americans from Foreign Adversary Controlled Applications Act – a law aimed at forcing TikTok's Chinese parent ByteDance to sell the app's US operations or face the prospect of a ban.…

☐ β˜† βœ‡ The Register - Security

Nissan to let 100,000 Aussies and Kiwis know their data was stolen in cyberattack

March 14th 2024 at 00:32

Akira ransomware crooks brag of swiping thousands of ID documents during break-in

Over the next few weeks, Nissan Oceania will make contact with around 100,000 people in Australia and New Zealand whose data was pilfered in a December 2023 attack on its systems – perhaps by the Akira ransomware gang.…

☐ β˜† βœ‡ The Register - Security

Poking holes in Google tech bagged bug hunters $10M

March 13th 2024 at 18:00

A $2M drop from previous year. So … things are more secure?

Google awarded $10 million to 632 bug hunters last year through its vulnerability reward programs.…

☐ β˜† βœ‡ The Register - Security

Cryptocurrency laundryman gets hung out to dry

March 13th 2024 at 16:45

Bitcoin Fog washed hundreds of millions for criminals

The operator of the world's longest-running Bitcoin money laundering service faces a 50-year prison sentence after being found guilty in a US court.…

☐ β˜† βœ‡ The Register - Security

Microsoft Copilot for Security prepares for April liftoff

March 13th 2024 at 16:00

Automated AI helper intended to make security more manageable

Microsoft Copilot for Security, a subscription AI security service, will be generally available on April 1, 2024, the company announced on Wednesday.…

☐ β˜† βœ‡ The Register - Security

Stanford University failed to detect ransomware intruders for 4 months

March 13th 2024 at 12:05

27,000 individuals had data stolen, which for some included names and social security numbers

Stanford University says the cybersecurity incident it dealt with last year was indeed ransomware, which it failed to spot for more than four months.…

☐ β˜† βœ‡ The Register - Security

Reducing the cloud security overhead

March 13th 2024 at 08:51

Why creating a layered defensive strategy that includes security by design can help address cloud challenges

Sponsored Feature The world is filled with choices. Whether it's the 20 different types of shampoo on offer at the grocery store, or the dozens of Linux distros you can try for free, you can have it all.…

☐ β˜† βœ‡ The Register - Security

Whizkids jimmy OpenAI, Google's closed models

March 13th 2024 at 08:34

Infosec folk aren’t thrilled that if you poke APIs enough, you learn AI's secrets

Boffins have managed to pry open closed AI services from OpenAI and Google with an attack that recovers an otherwise hidden portion of transformer models.…

☐ β˜† βœ‡ The Register - Security

March Patch Tuesday sees Hyper-V join the guest-host escape club

March 13th 2024 at 00:16

Critical bugs galore among 61 Microsoft fixes, 56 from Adobe, a dozen from SAP, and a fistful from Fortinet

Patch Tuesday Microsoft's monthly patch drop has arrived, delivering a mere 61 CVE-tagged vulnerabilities – none listed as under active attack or already known to the public.…

☐ β˜† βœ‡ The Register - Security

Meta sues ex infra VP for allegedly stealing top-secret datacenter blueprints

March 12th 2024 at 22:39

Exec accused of using own work PC to swipe confidential AI and staffing docs for stealth cloud startup

An ex-Meta veep has been sued by his former bosses for "brazenly disloyal and dishonest conduct" – and by that, they mean he allegedly stole confidential documents to help him build and recruit colleagues for an AI cloud startup. …

☐ β˜† βœ‡ The Register - Security

Biden's budget proposal boosts CISA funding to $3B

March 12th 2024 at 18:30

Plus almost $1.5b for health-care cybersecurity

US President Joe Biden has asked Congress to approve an extra $103 million in funding for the Cybersecurity and Infrastructure Security Agency, bringing CISA's total budget to $3 billion.…

☐ β˜† βœ‡ The Register - Security

JetBrains is still mad at Rapid7 for the ransomware attacks on its customers

March 12th 2024 at 16:30

War of words wages on between vendors divided

Last week, we wrote about how security outfit Rapid7 threw JetBrains, the company behind the popular CI/CD platform TeamCity, under the bus over allegations of silent patching. Now, JetBrains has gone on the offensive.…

☐ β˜† βœ‡ The Register - Security

UK council yanks IT systems and phone lines offline following cyber ambush

March 12th 2024 at 11:45

Targeting recovery this week, officials still trying to 'dentify the nature of the incident'

Leicester City Council says IT systems and a number of its critical service phone lines will remain down until later this week at the earliest following a "cyber incident".…

☐ β˜† βœ‡ The Register - Security

French government sites disrupted by très grande DDoS

March 12th 2024 at 06:26

Russia and Sudan top the list of suspects

Several French government websites have been disrupted by a severe distributed denial of service attack.…

☐ β˜† βœ‡ The Register - Security

White House and lawmakers increase pressure on UnitedHealth to ease providers' pain

March 12th 2024 at 00:02

US senator calls cyber attack 'inexcusable,' calls for mandatory security rules

The Biden administration and US lawmakers are turning up the pressure on UnitedHealth group to ease medical providers' pain after the ransomware attack on Change Healthcare, by expediting payments to hospitals, physicians and pharmacists – among other tactics.…

☐ β˜† βœ‡ The Register - Security

Kremlin accuses America of plotting cyberattack on Russian voting systems

March 11th 2024 at 21:58

Don't worry, we have a strong suspicion Putin's still gonna win

The Kremlin has accused the United States of meddling in Russia's upcoming presidential election, and even accused Uncle Sam of planning a cyberattack on the country's online voting system.…

☐ β˜† βœ‡ The Register - Security

British Library pushes the cloud button, says legacy IT estate cause of hefty rebuild

March 11th 2024 at 13:30

Five months in and the mammoth post-ransomware recovery has barely begun

The British Library says legacy IT is the overwhelming factor delaying efforts to recover from the Rhysida ransomware attack in late 2023.…

☐ β˜† βœ‡ The Register - Security

How do you lot feel about Pay or say OK to ads model, asks ICO

March 11th 2024 at 11:16

And does it count as consent?

The UK's Information Commissioner's Office (ICO) has opened a consultation on "consent or pay" business models. We're sure readers of The Register will have a fair few things to say.…

☐ β˜† βœ‡ The Register - Security

Microsoft waited 6 months to patch actively exploited admin-to-kernel vulnerability

March 11th 2024 at 04:28

PLUS: NSA shares cloud security tips; Infosec training for Jordanian women; Critical vulnerabilities

Infosec in brief Cybersecurity researchers informed Microsoft that Notorious North Korean hackers Lazarus Group discovered the "holy grail" of rootkit vulnerabilities in Windows last year, but Redmond still took six months to patch the problem.…

☐ β˜† βœ‡ The Register - Security

Cybercrime crew Magnet Goblin bursts onto the scene exploiting Ivanti holes

March 8th 2024 at 22:55

Plus: CISA pulls plug on couple of systems feared compromised

There's yet another group of miscreants out there hijacking insecure Ivanti devices: A new, financially motivated gang dubbed Magnet Goblin has emerged from the shadowy digital depths with a knack for rapidly exploiting newly disclosed vulnerabilities before vendors have issued a fix.…

☐ β˜† βœ‡ The Register - Security

Microsoft confirms Russian spies stole source code, accessed internal systems

March 8th 2024 at 16:56

Still 'no evidence' of any compromised customer-facing systems, we're told

Microsoft has now confirmed that the Russian cyberspies who broke into its executives' email accounts stole source code and gained access to internal systems. The Redmond giant also characterized the intrusion as "ongoing."…

☐ β˜† βœ‡ The Register - Security

Change Healthcare registers pulse after crippling ransomware attack

March 8th 2024 at 14:33

Remaining services are expected to return in the coming weeks after $22M ALPHV ransom

Change Healthcare has taken the first steps toward a full recovery from the ransomware attack in February by bringing its electronic prescription services back online.…

☐ β˜† βœ‡ The Register - Security

Chrome users – get an alert when extensions are in danger of falling into wrong hands

March 7th 2024 at 19:45

Under New Management is an early-warning system for potential poisoning of add-ons with malware

Millions of Chrome users now have a way to guard against the threat of extension subversion, that is, if they don't mind installing yet another browser extension.…

☐ β˜† βœ‡ The Register - Security

Swiss cheese security? Play ransomware gang milks government of 65,000 files

March 8th 2024 at 12:35

Classified docs, readable passwords, and thousands of personal information nabbed in Xplain breach

The Swiss government had around 65,000 files related to it stolen by the Play ransomware gang during an attack on an IT supplier, its National Cyber Security Center (NCSC) says.…

☐ β˜† βœ‡ The Register - Security

Font security 'still a Helvetica of a problem' says Australian graphics outfit Canva

March 8th 2024 at 03:57

Who knew that unzipping a font archive could unleash a malicious file

Online graphic design platform Canva went looking for security problems in fonts, and found three – in "strange places."…

☐ β˜† βœ‡ The Register - Security

Securing open source software: Whose job is it, anyway?

March 8th 2024 at 01:02

CISA announces more help, and calls on app makers to step up

The US government and some of the largest open source foundations and package repositories have announced a series of initiatives intended to improve software supply-chain security, while also repeating calls for developers to increase support for such efforts.…

☐ β˜† βœ‡ The Register - Security

We're not Meta support: State AGs tell Zuck to fix rampant account takeover problem

March 7th 2024 at 21:45

'We refuse to operate as customer service representatives'

A group of 41 US state attorneys general, tired of serving as a customer complaint clearinghouse for Facebook and Instagram users, have sent a letter to Meta asking it to figure out how to reduce a "dramatic and persistent spike" in account takeovers.…

☐ β˜† βœ‡ The Register - Security

Possible China link to Change Healthcare ransomware attack

March 7th 2024 at 18:30

Alleged crim bought SmartScreen Killer, Cobalt Strike on dark-web markets

A criminal claiming to be an ALPHV/BlackCat affiliate β€” the gang responsible for the widely disruptive Change Healthcare ransomware infection last month β€”Β  may have ties to Chinese government-backed cybercrime syndicates.…

☐ β˜† βœ‡ The Register - Security

JetBrains TeamCity under attack by ransomware thugs after disclosure mess

March 7th 2024 at 16:34

More than 1,000 servers remain unpatched and vulnerable

Security researchers are increasingly seeing active exploit attempts using the latest vulnerabilities in JetBrains' TeamCity that in some cases are leading to ransomware deployment.…

☐ β˜† βœ‡ The Register - Security

Belgian ale legend Duvel's brewery borked as ransomware halts production

March 7th 2024 at 12:45

Biz reassures quaffers it has enough beer, expects quick recovery before weekend

Belgian beer brewer Duvel says a ransomware attack has brought its facility to a standstill while its IT team works to remediate the damage.…

☐ β˜† βœ‡ The Register - Security

VMware urges emergency action to blunt hypervisor flaws

March 7th 2024 at 07:30

Critical vulns in USB under ESXi and desktop hypervisors found by Chinese researchers at cracking contest

Hypervisors are supposed to provide an inviolable isolation layer between virtual machines and hardware. But hypervisor heavyweight VMware by Broadcom yesterday revealed its hypervisors are not quite so inviolable as it might like.…

☐ β˜† βœ‡ The Register - Security

Reminder: Infostealer malware is coming for your ChatGPT credentials

March 7th 2024 at 06:27

Singaporean researchers note rising presence of OpenAI logins in infostealer malware logs

Stolen ChatGPT credentials are a hot commodity on the dark web, according to Singapore-based threat intelligence firm Group-IB, which claims to have found some 225,000 log files containing login details for the service last year.…

☐ β˜† βœ‡ The Register - Security

US politicians want ByteDance to sell off TikTok or face ban

March 7th 2024 at 06:05

The American mind must not be at the mercy of Chinese algorithms

A group of US lawmakers introduced legislation on Tuesday that, if passed, would force Chinese internet concern ByteDance to divest TikTok – its most valuable property – or see it banned in the US.…

☐ β˜† βœ‡ The Register - Security

Lawsuit claims gift card fraud is the gift that keeps on giving, to Google

March 7th 2024 at 01:15

Play Store commissions are a nice little earner, wherever they come from

Google has been accused of profiting from gift card scams.…

☐ β˜† βœ‡ The Register - Security

Chinese chap charged with stealing Google’s AI datacenter secrets

March 7th 2024 at 00:37

Moonlighted for PRC companies after side-stepping Big G's security, allegedly

A now-former Google employee has been charged with stealing the ad giant’s AI trade secrets while quietly working for two Chinese companies – after easily defeating whatever security controls Big G had in place.…

☐ β˜† βœ‡ The Register - Security

FBI: Critical infrastructure suffers spike in ransomware attacks

March 6th 2024 at 20:49

Jump in overall cybercrime reports, $60M-plus reportedly lost to extortionists alone, Feds reckon

Digital crimes potentially cost victims more than $12.5 billion last year, according to the FBI's latest Internet Crime Complaint Center (IC3) annual report. …

☐ β˜† βœ‡ The Register - Security

Apple's trademark tight lips extend to new iPhone, iPad zero-days

March 6th 2024 at 17:01

Two flaws fixed, one knee bent to the EU, and a budding cybersecurity star feature in iOS 17.4

Apple's latest security patches address four vulnerabilities affecting iOS and iPadOS, including two zero-days that intel suggests attackers have already exploited.…

☐ β˜† βœ‡ The Register - Security

Capita says 2023 cyberattack costs a factor as it reports staggering Β£100M+ loss

March 6th 2024 at 12:31

Additional cuts announced, sparking fears of further layoffs

Outsourcing giant Capita today reported a net loss of Β£106.6 million ($135.6 million) for calendar 2023, with the costly cyberattack by criminals making a hefty dent in its annual financials.…

☐ β˜† βœ‡ The Register - Security

Chip lobby group SEMI to EU: Export restrictions should only be used in self-defense

March 6th 2024 at 08:23

Please don't scare away foreign investors - who do you think pays for this stuff?

SEMI, an industry association representing 3,000 chip vendors, would really appreciate it if the European Union would back off plans to impose export controls on China, arguing that they should only be used as a "last resort" to protect national security.…

☐ β˜† βœ‡ The Register - Security

Japan orders local giants LINE and NAVER to disentangle their tech stacks

March 6th 2024 at 03:29

Government mighty displeased about a shared Active Directory that led to a big data leak

Japan's government has ordered local tech giants LINE and NAVER to disentangle their tech stacks, after a data breach saw over 510,000 users' data exposed.…

☐ β˜† βœ‡ The Register - Security

Uncle Sam intervenes as Change Healthcare ransomware fiasco creates mayhem

March 6th 2024 at 00:30

As the crooks behind the attack - probably ALPHV/BlackCat - fake their own demise

The US government has stepped in to help hospitals and other healthcare providers affected by the Change Healthcare ransomware infection, offering more relaxed Medicare rules and urging advanced funding to providers.…

☐ β˜† βœ‡ The Register - Security

Fidelity customers' financial info feared stolen in suspected ransomware attack

March 5th 2024 at 19:28

Insurance giant blames Infosys, LockBit claims credit

Criminals have probably stolen nearly 30,000 Fidelity Investments Life Insurance customers' personal and financial information β€” including bank account and routing numbers, credit card numbers and security or access codes β€” after breaking into Infosys' IT systems in the fall.…

☐ β˜† βœ‡ The Register - Security

US accuses Army vet cyber-Casanova of sharing Russia-Ukraine war secrets

March 5th 2024 at 17:06

Where better to expose confidential data than on a dating app?

Yet another US military man is facing a potentially significant stretch in prison after allegedly sending secret national defense information (NDI) overseas.…

☐ β˜† βœ‡ The Register - Security

IP address X-posure now a feature on Musk's social media thing

March 5th 2024 at 16:18

Just a little FYI

Video and audio calling features for X Premium users added last year to Elon Musk's version of Twitter have been expanded to everyone on the platform, and FYI: It may reveal your IP address to those you're nattering away to.…

☐ β˜† βœ‡ The Register - Security

Rapid7 throws JetBrains under the bus for 'uncoordinated vulnerability disclosure'

March 5th 2024 at 13:15

Exploits began within hours of the original disclosure, so patch now

Updated Security shop Rapid7 is criticizing JetBrains for flouting its policy against silent patching regarding fixes for two fresh vulnerabilities in the TeamCity CI/CD server.…

☐ β˜† βœ‡ The Register - Security

Spam crusade lands charity in hot water with data watchdog

March 5th 2024 at 09:30

Penny Appeal sent more than 460,000 texts asking for money to help war-torn countries, no opt out

Typically it is energy improvement peddlers or debt help specialists that are disgraced by Britain's data watchdog for spamming unsuspecting households, but the latest entrant in the hall of shame is a charity.…

☐ β˜† βœ‡ The Register - Security

Cloudflare wants to put a firewall in front of your LLM

March 5th 2024 at 01:32

Claims to protect against DDoS, sensitive data leakage

Cloudflare has tweaked its web application firewall (WAF) to add protections for applications using large language models.…

☐ β˜† βœ‡ The Register - Security

American Express admits card data exposed and blames third party

March 4th 2024 at 23:04

Don't leave home without … IT security

A security failure at a third-party vendor exposed an untold number of American Express card numbers, expiry dates, and other data to persons unknown.…

☐ β˜† βœ‡ The Register - Security

Change Healthcare attack latest: ALPHV bags $22M in Bitcoin amid affiliate drama

March 4th 2024 at 21:01

No honor among thieves?

ALPHV/BlackCat, the gang behind the Change Healthcare cyberattack, has received more than $22 million in Bitcoin in what might be a ransomware payment.…

☐ β˜† βœ‡ The Register - Security

Seoul accuses North Korea of stealing southern chipmakers' designs

March 4th 2024 at 20:00

Kim Jong Un's all in for home-built silicon says warning

North Korean government spies have broken into the servers of at least two chipmakers and stolen product designs as part of attempts to spur Kim Jong Un's plans for a domestic semiconductor industry, according to Seoul's security agency.…

☐ β˜† βœ‡ The Register - Security

German defense chat overheard by Russian eavesdroppers on Cisco's WebEx

March 4th 2024 at 17:45

Officials can't tell whether the tape was edited, but fear Kremlin has more juicy bits to release in the future

The German Ministry of Defense (Bundeswehr) has confirmed that a recording of a call between high-ranking officials discussing war efforts in Ukraine, leaked by Russian media, is legitimate.…

☐ β˜† βœ‡ The Register - Security

Ransomware ban backers insist thugs must be cut off from payday

March 4th 2024 at 14:30

Increasingly clear number of permanent solutions is narrowing

Global law enforcement authorities' attempts to shutter the LockBit ransomware crew have sparked a fresh call for a ban on ransomware payments to perpetrators.…

☐ β˜† βœ‡ The Register - Security

The federal bureau of trolling hits LockBit, but the joke's on us

March 4th 2024 at 09:30

When you can't lock 'em up, lock 'em out

Opinion The best cop shows excel at mind games: who's tricking whom, who really wins, and what price they pay. A twist of humor adds to the drama and keeps us hooked. It's rare enough in real life, far less so in the grim meat grinder of cybersecurity, yet sometimes it happens. It's happening right now.…

☐ β˜† βœ‡ The Register - Security

LockBit's contested claim of fresh ransom payment suggests it's been well hobbled

March 4th 2024 at 03:15

ALSO: CISA warns Ivanti vuln mitigations might not work, SAML hijack doesn't need ADFS, and crit vulns

Infosec in brief The infamous LockBit ransomware gang has been busy in the ten days since an international law enforcement operation took down many of its systems. But despite its posturing, the gang might have suffered more than it's letting on.…

❌