FreshRSS

πŸ”’
☐ β˜† βœ‡ The Register - Security

NVD slowdown leaves thousands of vulnerabilities without analysis data

March 22nd 2024 at 13:45

Security world reacts as NIST does a lot less of oft criticized, 'almost always thankless' work

Opinion The United States National Institute of Standards and Technology (NIST) has almost completely stopped adding analysis to Common Vulnerabilities and Exposures (CVEs) listed in the National Vulnerability Database. That means big headaches for anyone using CVEs to maintain their security. …

☐ β˜† βœ‡ The Register - Security

Truck-to-truck worm could infect – and disrupt – entire US commercial fleet

March 22nd 2024 at 00:03

The device that makes it possible is required in all American big rigs, and has poor security

Vulnerabilities in common Electronic Logging Devices (ELDs) required in US commercial trucks could be present in over 14 million medium- and heavy-duty rigs, according to boffins at Colorado State University.…

☐ β˜† βœ‡ The Register - Security

FBI v the bots: Feds urge denial-of-service defense after critical infrastructure alert

March 21st 2024 at 22:20

You better watch out, you better not cry, better not pout, they're telling you why

The US government has recommended a series of steps that critical infrastructure operators should take to prevent distributed-denial-of-service (DDoS) attacks.…

☐ β˜† βœ‡ The Register - Security

Microsoft faces bipartisan criticism for alleged censorship on Bing in China

March 21st 2024 at 21:25

Redmond says it does what it's told, but still thinks users are better off

Microsoft is the subject of growing criticism in the US over allegations that its Bing search engine censors results for users in China that relate to sensitive subjects the state wants blocked.…

☐ β˜† βœ‡ The Register - Security

Congress votes unanimously to ban brokers selling American data to enemies

March 21st 2024 at 20:30

At least we can all agree on something

The US House of Representatives has passed a bill that would prohibit data brokers from selling Americans' data to foreign adversaries with an unusual degree of bipartisan support: It passed without a single opposing vote.…

☐ β˜† βœ‡ The Register - Security

Yacht dealer to the stars attacked by Rhysida ransomware gang

March 21st 2024 at 15:30

MarineMax may be in choppy waters after 'stolen data' given million-dollar price tag

The Rhysida ransomware group claims it was responsible for the cyberattack at US luxury yacht dealer MarineMax earlier this month.…

☐ β˜† βœ‡ The Register - Security

UK council won't say whether two-week 'cyber incident' impacted resident data

March 21st 2024 at 11:37

Security experts insist ransomware is involved but Leicester zips its lips

Leicester City Council continues to battle a suspected ransomware attack while keeping schtum about the key details.…

☐ β˜† βœ‡ The Register - Security

Exposed: Chinese smartphone farms that run thousands of barebones mobes to do crime

March 21st 2024 at 06:32

Operators pack twenty phones into a chassis – then rack 'em and stack 'em ready to do evil

Chinese upstarts are selling smartphone motherboards – and kit to run and manage them at scale – to operators of outfits that use them to commit various scams and crimes, according to an undercover investigation by state television broadcaster China Central Television (CCTV) revealed late last week.…

☐ β˜† βœ‡ The Register - Security

It's 2024 and North Korea's Kimsuky gang is exploiting Windows Help files

March 21st 2024 at 05:30

New infostealer may indicate a shift in tactics – and maybe targets too, beyond Asia

North Korea's notorious Kimsuky cyber crime gang has commenced a campaign using fresh tactics, according to infosec tools vendor Rapid7.…

☐ β˜† βœ‡ The Register - Security

It's tax season, and scammers are a step ahead of filers, Microsoft says

March 20th 2024 at 19:30

Phishing season started early with crims intent on the hooking early filers

As the digital wolves dress in sheep's tax forms, Microsoft has thrown a spotlight on a crafty 2024 phishing expedition, unraveled in January, that preys on the unsuspecting herd of early tax filers.…

☐ β˜† βœ‡ The Register - Security

US task force aims to plug security leaks in water sector

March 20th 2024 at 18:32

From a trickle to a flood, threats now seen as too great to ignore

US government is urging state officials to band together to improve the cybersecurity of the country's water sector amid growing threats from foreign adversaries.…

☐ β˜† βœ‡ The Register - Security

London Clinic probes claim staffer tried to peek at Princess Kate's records

March 20th 2024 at 15:30

First: Not being able buy a meat pie with a credit card. Now this

The London Clinic where the Princess of Wales had surgery at the start of this year says it is investigating claims an employee tried to access her medical records.…

☐ β˜† βœ‡ The Register - Security

Serial extortionist of medical facilities pleads guilty to cybercrime charges

March 20th 2024 at 14:33

Robert Purbeck even went as far as threatening a dentist with the sale of his child’s data

A cyberattacker and extortionist of a medical center has pleaded guilty to federal computer fraud and abuse charges in the US.…

☐ β˜† βœ‡ The Register - Security

Stalkerware usage surging, despite data privacy concerns

March 20th 2024 at 13:15

At least 31,031 people affected last year

Stalkerware has reached "pandemic proportions," according to Kaspersky, which documented a total of 31,031 people affected by the intrusive software in 2023 – up almost six percent on the prior year.…

☐ β˜† βœ‡ The Register - Security

Five Eyes tell critical infra orgs: Take these actions now to protect against China's Volt Typhoon

March 20th 2024 at 10:15

Unless you want to be the next Change Healthcare, that is

The Feds and friends yesterday issued yet another warning about China's Volt Typhoon gang, this time urging critical infrastructure owners and operators to protect their facilities against destructive cyber attacks that may be brewing.…

☐ β˜† βœ‡ The Register - Security

Australian techie jailed for accessing museum's accounting system and buying himself stuff

March 20th 2024 at 01:45

Also down under, researchers find security-cleared workers leaking details of their gigs

An Australian IT contractor has been sentenced to 30 months jail for ripping off the National Maritime Museum.…

☐ β˜† βœ‡ The Register - Security

Beijing-backed cyberspies attacked 70+ orgs across 23 countries

March 19th 2024 at 21:00

Plus potential links to I-Soon, researchers say

Chinese cyberspies have compromised at least 70 organizations, mostly government entities, and targeted more than 116 victims across the globe, according to security researchers.…

☐ β˜† βœ‡ The Register - Security

Crypto scams more costly to the US than ransomware, Feds say

March 19th 2024 at 20:00

Latest figures paint grim picture of how viciously the elderly are targeted

The FBI says investment fraud was the form of cybercrime that incurred the greatest financial loss for Americans last year.…

☐ β˜† βœ‡ The Register - Security

Crypto wallet providers urged to rethink security as criminals drain them of millions

March 19th 2024 at 14:30

Innovative Ethereum feature exploited as victims say goodbye to assets

Infosec researchers are noting rising cryptocurrency attacks and have encouraged wallet security providers to up their collective game.…

☐ β˜† βœ‡ The Register - Security

Atos says Airbus flew off, no longer interested in infosec and big data biz

March 19th 2024 at 12:30

Ailing tech integrator takes a hard hit... share price down by up to 20% this morning

Atos' share price sank as much as 20 percent this morning on confirmation that Airbus is no longer interested in buying the big data and security (BDS) parts of the crumbling tech empire.…

☐ β˜† βœ‡ The Register - Security

Don't be like these 900+ websites and expose millions of passwords via Firebase

March 18th 2024 at 21:29

Warning: Poorly configured Google Cloud databases spill billing info, plaintext credentials

At least 900 websites built with Google's Firebase, a cloud database, have been misconfigured, leaving credentials, personal info, and other sensitive data inadvertently exposed to the public internet, according to security researchers.…

☐ β˜† βœ‡ The Register - Security

Fujitsu: Miscreants infected our systems with malware, may have stolen customer info

March 18th 2024 at 20:30

Sneaky software slips past shields, spurring scramble

Fujitsu has confirmed that miscreants have compromised some of its internal computers, deployed malware, and may have stolen some customer information.…

☐ β˜† βœ‡ The Register - Security

More than 133,000 Fortinet appliances still vulnerable to month-old critical bug

March 18th 2024 at 19:00

A huge attack surface for a vulnerability with various PoCs available

The volume of Fortinet boxes exposed to the public internet and vulnerable to a month-old critical security flaw in FortiOS is still extremely high, despite a gradual increase in patching.…

☐ β˜† βœ‡ The Register - Security

Cyber baddies leak 70M+ files online, claim they're from AT&T

March 18th 2024 at 16:45

Telco reckons data is old, isn't from its systems

More than 70 million records, allegedly stolen from AT&T in 2021, were dumped on a cybercrime forum at the weekend.…

☐ β˜† βœ‡ The Register - Security

Cyberattack gifts esports pros with cheats, forcing Apex Legends to postpone tournament

March 18th 2024 at 13:15

Virtual gunslingers forcibly became cheaters via mystery means

Updated Esports pros competing in the Apex Legends Global Series (ALGS) Pro League tournament were forced to abandon their match today due to a suspected cyberattack.…

☐ β˜† βœ‡ The Register - Security

Infosec teams must be allowed to fail, argues Gartner

March 18th 2024 at 07:29

But failing to recover from incidents is unforgivable because 'adrenalin does not scale'

Zero tolerance of failure by information security professionals is unrealistic, and makes it harder for cyber security folk to do the essential part of their job: recovering fast from inevitable attacks, according to Gartner analysts Chris Mixter and Dennis Xu.…

☐ β˜† βœ‡ The Register - Security

Filipino police free hundreds of slaves toiling in romance scam operation

March 18th 2024 at 05:46

875 workers liberated after falling for promises of lucrative work, nine arrested

Filipino police rescued 875 "workers" – including 504 foreigners – in a raid late last week on a firm that posed as an online gaming company but in reality operated a forced labor camp that housed romance scam operators.…

☐ β˜† βœ‡ The Register - Security

Protecting distributed branch office environments from ransomware

March 18th 2024 at 03:00

As ransomware becomes more sophisticated, detection tools should be upgraded to cover every site and location

Sponsored Feature Ransomware gangs that steal and encrypt vital business data before extorting payment for its decryption and restoration are ramping up global attacks at an ever-increasing rate. In fact, cyber security experts agree that ransomware now represents one of - if not the most - serious cybersecurity threats currently facing governments, public/private sector organisations and enterprises around the world.…

☐ β˜† βœ‡ The Register - Security

ChatGPT side-channel attack has easy fix: Token obfuscation

March 18th 2024 at 02:31

Also: Roblox-themed infostealer on the prowl, telco insider pleads guilty to swapping SIMs, and some crit vulns

Infosec in brief Almost as quickly as a paper came out last week revealing an AI side-channel vulnerability, Cloudflare researchers have figured out how to solve it: just obscure your token size.…

☐ β˜† βœ‡ The Register - Security

In the rush to build AI apps, please, please don't leave security behind

March 17th 2024 at 11:04

Supply-chain attacks are definitely possible and could lead to data theft, system hijacking, and more

Feature While in a rush to understand, build, and ship AI products, developers and data scientists are being urged to be mindful of security and not fall prey to supply-chain attacks.…

☐ β˜† βœ‡ The Register - Security

As if working at Helldesk weren't bad enough, IT helpers now targeted by cybercrims

March 15th 2024 at 19:00

Wave of Okta attacks mark what researchers are calling the biggest security trend of the year

IT helpdesk workers are increasingly the target of cybercriminals – a trend researchers have described as "the most noteworthy" of the past year.…

☐ β˜† βœ‡ The Register - Security

Cop shop rapped for 'completely avoidable' web form blunder

March 15th 2024 at 11:34

Made public highly sensitive data on complaints about Metropolitan Police Service

The London Mayor's Office for Policing and Crime is being rapped by regulators for untidy tech practices that made public the personal data of hundreds of people who filed complaints against the Metropolitan Police Service.…

☐ β˜† βœ‡ The Register - Security

Forget TikTok – Chinese spies want to steal IP by backdooring digital locks

March 14th 2024 at 23:35

Uncle Sam can use this snooping tool, too, but that's beside the point

Updated There's another Chinese-manufactured product – joining the likes of TikTok, cars and semiconductors – that poses a national security risk to Americans: Electronic locks, such as those used in safes.…

☐ β˜† βœ‡ The Register - Security

FTC goes undercover to probe suspected antivirus scam, scores $26M settlement

March 14th 2024 at 20:24

Imagine trying to trick folks into buying $500 of unnecessary repairs – and they turn out to be federal agents

A pair of tech support businesses accused of swindling marks out of their hard-earned cash have agreed to cough up a $26 million settlement following an undercover probe by the FTC.…

☐ β˜† βœ‡ The Register - Security

LockBit ransomware kingpin gets 4 years behind bars

March 14th 2024 at 18:26

Canadian-Russian said to have turned to a life of cybercrime during pandemic, now must pay the price – literally

A LockBit ransomware kingpin has been sentenced to almost four years behind bars and ordered to pay more than CA$860,000 ($635,000, Β£500,000) in restitution to some of his victims by a Canadian court as he awaits extradition to the US.…

☐ β˜† βœ‡ The Register - Security

Google gooses Safe Browsing with real-time protection that doesn't leak to ad giant

March 14th 2024 at 17:58

Rare occasion when you do want Big Tech to make a hash of it

Google has enhanced its Safe Browsing service to enable real-time protection in Chrome for desktop, iOS, and soon Android against risky websites, without sending browsing history data to the ad biz.…

☐ β˜† βœ‡ The Register - Security

Record breach of French government exposes up to 43 million people's data

March 14th 2024 at 16:06

Zut alors! Department for registering and helping unemployed people broken into

A French government department - responsible for registering and assisting unemployed people - is the latest victim of a mega data breach that compromised the information of up to 43 million citizens.…

☐ β˜† βœ‡ The Register - Security

International effort to disrupt cybercrime moves into operational phase

March 14th 2024 at 15:00

Will the WEF experiment work?

The Cybercrime Atlas, a massive undertaking that aims to disrupt cybercriminals across the globe, enters its operational phase in 2024, two years after organizers laid the groundwork at the RSA Conference.…

☐ β˜† βœ‡ The Register - Security

US to probe Change Healthcare's data protection standards as lawsuits mount

March 14th 2024 at 14:03

Services slowly coming back online but providers still struggling

Change Healthcare is being investigated over the alleged 6 TB data theft by the ALPHV ransomware group as it continues recovery efforts.…

☐ β˜† βœ‡ The Register - Security

US Congress goes bang, bang, on TikTok sale-or-ban plan

March 14th 2024 at 01:46

Bill proposes to do to China what China already does to the US – make life hard for foreign social networks

The United States House of Representatives on Wednesday passed the Protecting Americans from Foreign Adversary Controlled Applications Act – a law aimed at forcing TikTok's Chinese parent ByteDance to sell the app's US operations or face the prospect of a ban.…

☐ β˜† βœ‡ The Register - Security

Nissan to let 100,000 Aussies and Kiwis know their data was stolen in cyberattack

March 14th 2024 at 00:32

Akira ransomware crooks brag of swiping thousands of ID documents during break-in

Over the next few weeks, Nissan Oceania will make contact with around 100,000 people in Australia and New Zealand whose data was pilfered in a December 2023 attack on its systems – perhaps by the Akira ransomware gang.…

☐ β˜† βœ‡ The Register - Security

Poking holes in Google tech bagged bug hunters $10M

March 13th 2024 at 18:00

A $2M drop from previous year. So … things are more secure?

Google awarded $10 million to 632 bug hunters last year through its vulnerability reward programs.…

☐ β˜† βœ‡ The Register - Security

Cryptocurrency laundryman gets hung out to dry

March 13th 2024 at 16:45

Bitcoin Fog washed hundreds of millions for criminals

The operator of the world's longest-running Bitcoin money laundering service faces a 50-year prison sentence after being found guilty in a US court.…

☐ β˜† βœ‡ The Register - Security

Microsoft Copilot for Security prepares for April liftoff

March 13th 2024 at 16:00

Automated AI helper intended to make security more manageable

Microsoft Copilot for Security, a subscription AI security service, will be generally available on April 1, 2024, the company announced on Wednesday.…

☐ β˜† βœ‡ The Register - Security

Stanford University failed to detect ransomware intruders for 4 months

March 13th 2024 at 12:05

27,000 individuals had data stolen, which for some included names and social security numbers

Stanford University says the cybersecurity incident it dealt with last year was indeed ransomware, which it failed to spot for more than four months.…

☐ β˜† βœ‡ The Register - Security

Reducing the cloud security overhead

March 13th 2024 at 08:51

Why creating a layered defensive strategy that includes security by design can help address cloud challenges

Sponsored Feature The world is filled with choices. Whether it's the 20 different types of shampoo on offer at the grocery store, or the dozens of Linux distros you can try for free, you can have it all.…

☐ β˜† βœ‡ The Register - Security

Whizkids jimmy OpenAI, Google's closed models

March 13th 2024 at 08:34

Infosec folk aren’t thrilled that if you poke APIs enough, you learn AI's secrets

Boffins have managed to pry open closed AI services from OpenAI and Google with an attack that recovers an otherwise hidden portion of transformer models.…

☐ β˜† βœ‡ The Register - Security

March Patch Tuesday sees Hyper-V join the guest-host escape club

March 13th 2024 at 00:16

Critical bugs galore among 61 Microsoft fixes, 56 from Adobe, a dozen from SAP, and a fistful from Fortinet

Patch Tuesday Microsoft's monthly patch drop has arrived, delivering a mere 61 CVE-tagged vulnerabilities – none listed as under active attack or already known to the public.…

☐ β˜† βœ‡ The Register - Security

Meta sues ex infra VP for allegedly stealing top-secret datacenter blueprints

March 12th 2024 at 22:39

Exec accused of using own work PC to swipe confidential AI and staffing docs for stealth cloud startup

An ex-Meta veep has been sued by his former bosses for "brazenly disloyal and dishonest conduct" – and by that, they mean he allegedly stole confidential documents to help him build and recruit colleagues for an AI cloud startup. …

☐ β˜† βœ‡ The Register - Security

Biden's budget proposal boosts CISA funding to $3B

March 12th 2024 at 18:30

Plus almost $1.5b for health-care cybersecurity

US President Joe Biden has asked Congress to approve an extra $103 million in funding for the Cybersecurity and Infrastructure Security Agency, bringing CISA's total budget to $3 billion.…

☐ β˜† βœ‡ The Register - Security

JetBrains is still mad at Rapid7 for the ransomware attacks on its customers

March 12th 2024 at 16:30

War of words wages on between vendors divided

Last week, we wrote about how security outfit Rapid7 threw JetBrains, the company behind the popular CI/CD platform TeamCity, under the bus over allegations of silent patching. Now, JetBrains has gone on the offensive.…

☐ β˜† βœ‡ The Register - Security

UK council yanks IT systems and phone lines offline following cyber ambush

March 12th 2024 at 11:45

Targeting recovery this week, officials still trying to 'dentify the nature of the incident'

Leicester City Council says IT systems and a number of its critical service phone lines will remain down until later this week at the earliest following a "cyber incident".…

☐ β˜† βœ‡ The Register - Security

French government sites disrupted by très grande DDoS

March 12th 2024 at 06:26

Russia and Sudan top the list of suspects

Several French government websites have been disrupted by a severe distributed denial of service attack.…

☐ β˜† βœ‡ The Register - Security

White House and lawmakers increase pressure on UnitedHealth to ease providers' pain

March 12th 2024 at 00:02

US senator calls cyber attack 'inexcusable,' calls for mandatory security rules

The Biden administration and US lawmakers are turning up the pressure on UnitedHealth group to ease medical providers' pain after the ransomware attack on Change Healthcare, by expediting payments to hospitals, physicians and pharmacists – among other tactics.…

☐ β˜† βœ‡ The Register - Security

Kremlin accuses America of plotting cyberattack on Russian voting systems

March 11th 2024 at 21:58

Don't worry, we have a strong suspicion Putin's still gonna win

The Kremlin has accused the United States of meddling in Russia's upcoming presidential election, and even accused Uncle Sam of planning a cyberattack on the country's online voting system.…

☐ β˜† βœ‡ The Register - Security

British Library pushes the cloud button, says legacy IT estate cause of hefty rebuild

March 11th 2024 at 13:30

Five months in and the mammoth post-ransomware recovery has barely begun

The British Library says legacy IT is the overwhelming factor delaying efforts to recover from the Rhysida ransomware attack in late 2023.…

☐ β˜† βœ‡ The Register - Security

How do you lot feel about Pay or say OK to ads model, asks ICO

March 11th 2024 at 11:16

And does it count as consent?

The UK's Information Commissioner's Office (ICO) has opened a consultation on "consent or pay" business models. We're sure readers of The Register will have a fair few things to say.…

☐ β˜† βœ‡ The Register - Security

Microsoft waited 6 months to patch actively exploited admin-to-kernel vulnerability

March 11th 2024 at 04:28

PLUS: NSA shares cloud security tips; Infosec training for Jordanian women; Critical vulnerabilities

Infosec in brief Cybersecurity researchers informed Microsoft that Notorious North Korean hackers Lazarus Group discovered the "holy grail" of rootkit vulnerabilities in Windows last year, but Redmond still took six months to patch the problem.…

☐ β˜† βœ‡ The Register - Security

Cybercrime crew Magnet Goblin bursts onto the scene exploiting Ivanti holes

March 8th 2024 at 22:55

Plus: CISA pulls plug on couple of systems feared compromised

There's yet another group of miscreants out there hijacking insecure Ivanti devices: A new, financially motivated gang dubbed Magnet Goblin has emerged from the shadowy digital depths with a knack for rapidly exploiting newly disclosed vulnerabilities before vendors have issued a fix.…

☐ β˜† βœ‡ The Register - Security

Microsoft confirms Russian spies stole source code, accessed internal systems

March 8th 2024 at 16:56

Still 'no evidence' of any compromised customer-facing systems, we're told

Microsoft has now confirmed that the Russian cyberspies who broke into its executives' email accounts stole source code and gained access to internal systems. The Redmond giant also characterized the intrusion as "ongoing."…

❌