FreshRSS

πŸ”’
☐ β˜† βœ‡ The Register - Security

Kaspersky hits back at claims its AI helped Russia develop military drone systems

May 3rd 2024 at 21:30

Ready, set, sanctions?

AI built by Russian infosec firm Kaspersky was used in Russian drones for its war on Ukraine, volunteer intelligence gatherers claim.…

☐ β˜† βœ‡ The Register - Security

It may take decade to shore up software supply chain security, says infosec CEO

May 3rd 2024 at 17:30

Sure, we're waking to the risk, but we gotta get outta bed, warns Endor Labs founder Varun Badhwar

interview The more cybersecurity news you read, the more often you seem to see a familiar phrase: Software supply chain (SSC) vulnerabilities. Varun Badhwar, founder and CEO at security firm Endor Labs, doesn't believe that's by coincidence. …

☐ β˜† βœ‡ The Register - Security

Europol op shutters 12 scam call centers and cuffs 21 suspected fraudsters

May 3rd 2024 at 05:34

Cops prevented crims from bilking victims out of more than €10m - but couldn't stop crime against art

A Europol-led operation dubbed β€œPandora” has shut down a dozen phone scam centers, and arrested 21 suspects. The cops reckon the action prevented criminals from bilking victims out of more than €10 million (Β£8.6 million, $11 million).…

☐ β˜† βœ‡ The Register - Security

Indonesia sneakily buys spyware, claims Amnesty International

May 3rd 2024 at 04:33

A 'murky' web sees many purchases run through Singapore in a way that hides potential users

Indonesia has acquired spyware and surveillance technologies through a "murky network" that extends into Israel, Greece, Singapore and Malaysia for equipment sourcing, according to Amnesty International.…

☐ β˜† βœ‡ The Register - Security

Chinese government website security is often worryingly bad, say Chinese researchers

May 3rd 2024 at 02:34

Bad configurations, insecure versions of jQuery, and crummy cookies are some of myriad problems

Exclusive Five Chinese researchers examined the configurations of nearly 14,000 government websites across the country and found worrying lapses that could lead to malicious attacks, according to a not-yet-peer-reviewed study released last week.…

☐ β˜† βœ‡ The Register - Security

Microsoft, Google do a victory lap around passkeys

May 2nd 2024 at 23:03

Windows giant extends passwordless tech to everyone else

Microsoft today said it will now let us common folk β€” not just commercial subscribers β€” signΒ into their Microsoft accounts and apps using passkeys with their face, fingerprint, or device PIN.…

☐ β˜† βœ‡ The Register - Security

Florida man gets 6 years behind bars for flogging fake Cisco kit to US military

May 2nd 2024 at 20:58

Operation busted after dodgy devices ended up at Air Force

Miami resident Onur Aksoy has been sentenced to six and a half years in prison for running a multi-million-dollar operation selling fake Cisco equipment that ended up in the US military.…

☐ β˜† βœ‡ The Register - Security

Patch up – 4 critical bugs in ArubaOS lead to remote code execution

May 2nd 2024 at 20:30

Ten vulnerabilities in total for admins to apply

Network admins are being urged to patch a bundle of critical vulnerabilities in ArubaOS that lead to remote code execution as a privileged user.…

☐ β˜† βœ‡ The Register - Security

Federal frenzy to patch gaping GitLab account takeover hole

May 2nd 2024 at 14:15

Warning comes exactly a year after the vulnerability was introduced

The US Cybersecurity and Infrastructure Security Agency (CISA) is forcing all federal agencies to patch a critical vulnerability in GitLab's Community and Enterprise editions, confirming it is very much under "active exploit."…

☐ β˜† βœ‡ The Register - Security

Think tank: China's tech giants refine and define Beijing's propaganda push

May 2nd 2024 at 06:57

Taking down TikTok won't stop the CCP's attempt to control global narratives

Chinese tech companies that serve as important links in the world's digital supply chains are helping Beijing to execute and refine its propaganda strategy, according to an Australian think tank.…

☐ β˜† βœ‡ The Register - Security

REvil ransomware scum sentenced to almost 14 years inside, ordered to pay $16 million

May 2nd 2024 at 06:31

After extorting $700 million from thousands of victims

A Ukrainian man has been sentenced to almost 14 years in prison and ordered to pay more than $16 million in restitution for his role in infecting thousands of victims with REvil ransomware.…

☐ β˜† βœ‡ The Register - Security

A million Australian pubgoers wake up to find personal info listed on leak site

May 2nd 2024 at 04:01

Man arrested and blackmail charges expected after allegations of unpaid contractors and iffy infosec

Updated Over a million records describing Australians who visited local pubs and clubs have apparently been posted online.…

☐ β˜† βœ‡ The Register - Security

Dropbox dropped the ball on security, haemorrhaging customer and third-party info

May 2nd 2024 at 00:58

Only from its digital doc-signing service, which is isolated from its cloudy storage

Dropbox has revealed a major attack on its systems that saw customers' personal information accessed by unknown and unauthorized entities.…

☐ β˜† βœ‡ The Register - Security

Block accused of mass compliance failures that saw digi-dollars reach terrorists

May 2nd 2024 at 00:30

Developer of Square and Cash App reportedly has big back-end problems it was slow to fix

Fintech biz Block is reportedly under investigation by US prosecutors over claims by a former employee that lax compliance checks mean its Square and Cash App services may have been used by terrorists – or in countries that US orgs are not permitted to do business.…

☐ β˜† βœ‡ The Register - Security

Infosec biz boss accused of BS'ing the world about his career, anti-crime product, customers

May 1st 2024 at 18:58

Intrusion investors went through Blount farce trauma, says SEC

Jack Blount, the now-ex CEO of Intrusion, has settled with the SEC over allegations he made false and misleading statements about his infosec firm's product as well as his own background and experience.…

☐ β˜† βœ‡ The Register - Security

US charges 16 over 'depraved' grandparent scams

May 1st 2024 at 17:00

Vulnerable elderly people tricked into paying tens of thousands over fake car accidents

Sixteen people are facing charges from US prosecutors for allegedly preying on the elderly and scamming them out of millions of dollars.…

☐ β˜† βœ‡ The Register - Security

Qantas app glitch sees boarding passes fly to other accounts

May 1st 2024 at 15:03

Issue now resolved and isn't thought to be the work of criminals

Aussie airline Qantas says its app is now stable following a data breach that saw boarding passes take off from passengers' accounts.…

☐ β˜† βœ‡ The Register - Security

Open source programming language R patches gnarly arbitrary code exec flaw

May 1st 2024 at 00:59

An ACE in the hole for miscreants

Updated The open source R programming language – popular among statisticians and data scientists for performing visualization, machine learning, and suchlike – has patched an arbitrary code execution hole that scored a preliminary CVSS severity rating of 8.8 out of 10.…

☐ β˜† βœ‡ The Register - Security

Cyber-bastard jailed for stealing psychotherapy files, blackmailing patients

April 30th 2024 at 23:26

Vastaamo villain more than doubled reported crime in Nordic nation

A cyber-thief who snatched tens of thousands of patients' sensitive records from a psychotherapy clinic before blackmailing them and then leaking their files online has been caged for six years and three months.…

☐ β˜† βœ‡ The Register - Security

UnitedHealth CEO: 'Decision to pay ransom was mine'

April 30th 2024 at 19:51

Congress to hear how Citrix MFA snafu led to massive data theft, $870M+ loss

Updated UnitedHealth CEO Andrew Witty will tell US lawmakers Wednesday the cybercriminals who hit Change Healthcare with ransomware used stolen credentials to remotely access a Citrix portal that didn't have multi-factor authentication enabled.…

☐ β˜† βœ‡ The Register - Security

NSA guy who tried and failed to spy for Russia gets 262 months in the slammer

April 30th 2024 at 17:01

Tried to sell top secret docs for the low, low price of $85K

A former NSA employee has been sentenced to 262 months in prison for attempting to freelance as a Russian spy.…

☐ β˜† βœ‡ The Register - Security

European Commission starts formal probe of Meta over election misinformation

April 30th 2024 at 12:30

Europe takes action after Facebook parent withdraws monitoring tool

The European Commission has launched formal proceedings against Meta, alleging failure to properly monitor distribution by "foreign actors" of political misinformation before June's European elections.…

☐ β˜† βœ‡ The Register - Security

Apple's 'incredibly private' Safari is not so private in Europe

April 30th 2024 at 07:24

Infosec eggheads find iGiant left EU iOS 17 users open to being tracked around the web

Apple's grudging accommodation of European antitrust rules by allowing third-party app stores on iPhones has left users of its Safari browser exposed to potential web activity tracking.…

☐ β˜† βœ‡ The Register - Security

AT&T, Verizon, Sprint, T-Mobile US fined $200M for selling off people's location info

April 29th 2024 at 23:20

Carriers claim real culprits are getting away with it - the data brokers

The FCC on Monday fined four major US telcos almost $200 million for "illegally" selling subscribers' location information to data brokers.…

☐ β˜† βœ‡ The Register - Security

Google blocked 2.3M apps from Play Store last year for breaking the G law

April 29th 2024 at 22:20

Third of a million developer accounts kiboshed, too

Google says it stopped 2.28 million Android apps from being published in its official Play Store last year because they violated security rules.…

☐ β˜† βœ‡ The Register - Security

London Drugs closes all of its pharmacies following 'cybersecurity incident'

April 29th 2024 at 18:21

Canadian stores shuttered 'until further notice'

Updated Canadian pharmacy chain London Drugs closed all of its stores over the weekend until further notice following a "cybersecurity incident."…

☐ β˜† βœ‡ The Register - Security

France willing to buy key Atos assets to keep them French

April 29th 2024 at 13:00

Finance minister says government has interests in IT giant's 'sovereign activities'

The French government has tabled an offer to buy key assets of ailing IT giant Atos after the company late last week almost doubled its estimate of the cash it will need to stay afloat in the near future.…

☐ β˜† βœ‡ The Register - Security

UK lays down fresh legislation banning crummy default device passwords

April 29th 2024 at 11:45

New laws mean vendors need to make clear how long you'll get updates too

Smart device manufacturers will have to play by new rules in the UK as of today, with laws coming into force to make it more difficult for cybercriminals to break into hardware such as phones and tablets.…

☐ β˜† βœ‡ The Register - Security

Watchdog reveals lingering Google Privacy Sandbox worries

April 29th 2024 at 10:15

Ad tech rewrite to replace web cookies still not to regulatory taste

The UK Competition and Markets Authority (CMA) still has privacy and competition concerns about Google's Privacy Sandbox advertising toolkit, which explains why the ad giant recently again delayed its plan to drop third-party cookies in Chrome until 2025.…

☐ β˜† βœ‡ The Register - Security

The next step up for high-impact identity authorization

April 29th 2024 at 02:45

How SSH Communications Security cuts through the hype around Zero Trust to secure the connections that matter

Sponsored Feature As business enters the 2020s, organizations find themselves protecting fast-expanding digital estates using security concepts that are decades old.…

☐ β˜† βœ‡ The Register - Security

Discord dismantles Spy.pet site that snooped on millions of users

April 29th 2024 at 02:29

ALSO: Infostealer spotted hiding in CDN cache, antivirus update hijacked to deliver virus, and some critical vulns

Updated - Infosec in brief They say sunlight is the best disinfectant, and that appears to have been true in the case of Discord data harvesting site Spy.pet – as it was recently and swiftly dismantled after its existence and purpose became known.…

☐ β˜† βœ‡ The Register - Security

Kaiser Permanente handed over 13.4M people's data to Microsoft, Google, others

April 26th 2024 at 18:14

Ouch!

Millions of Kaiser Permanente patients' data was likely handed over to Google, Microsoft Bing, X/Twitter, and other third-parties, according to the American healthcare giant.…

☐ β˜† βœ‡ The Register - Security

Second time lucky for Thoma Bravo, which scoops up Darktrace for $5.3B

April 26th 2024 at 16:00

Analysts brand deal a 'nail in the coffin' for UK tech investment

Private equity investor Thoma Bravo has successfully completed a second acquisition attempt of UK-based cybersecurity company Darktrace in a $5.3 billion deal.…

☐ β˜† βœ‡ The Register - Security

UK's Investigatory Powers Bill to become law despite tech world opposition

April 26th 2024 at 12:00

Only minor changes from original proposals that kicked up privacy storm

The UK's contentious Investigatory Powers (Amendment) Bill (IPB) 2024 has officially received the King's nod of approval and will become law.…

☐ β˜† βœ‡ The Register - Security

Four trends to top the CISO’s packed agenda

April 26th 2024 at 07:34

Check out the SANS CISO Primer for tips on hardening your organisation’s security posture in 2024

Sponsored Post Ever get nostalgic for the good old days of cybersecurity protection? When attacks were for the most part amateurish and infrequent, and perhaps more in the nature of an occasional nuisance rather than a daily existential threat?…

☐ β˜† βœ‡ The Register - Security

Flaws in Chinese keyboard apps leave 750 million users open to snooping, researchers claim

April 26th 2024 at 05:33

Huawei is OK, but Xiaomi, OPPO, and Samsung are in strife. And Honor isn't living its name

Many Chinese keyboard apps, some from major handset manufacturers, can leak keystrokes to determined snoopers, leaving perhaps three quarters of a billion people at risk according to research from the University of Toronto’s Citizen Lab.…

☐ β˜† βœ‡ The Register - Security

Cops cuff man for allegedly framing colleague with AI-generated hate speech clip

April 25th 2024 at 21:43

Athletics boss accused of deep-faking Baltimore school principal

Baltimore police have arrested Dazhon Leslie Darien, the former athletic director of Pikesville High School (PHS), for allegedly impersonating the school's principal using AI software to make it seem as if he made racist and antisemitic remarks.…

☐ β˜† βœ‡ The Register - Security

Ring dinged for $5.6M after, among other claims, rogue insider spied on 'pretty girls'

April 25th 2024 at 21:03

Cash to go out as refunds to punters

The FTC today announced it would be sending refunds totaling $5.6 million to Ring customers, paid from the Amazon subsidiary's coffers.…

☐ β˜† βœ‡ The Register - Security

Two cuffed in Samourai Wallet crypto dirty money sting

April 25th 2024 at 17:15

Suspects in Portugal and the US said to have laundered over $100M

Two men alleged to be co-founders of cryptocurrency biz Samourai Wallet face serious charges and potentially decades in US prison over claims they owned a product that facilitated the laundering of over $100 million in criminal cash.…

☐ β˜† βœ‡ The Register - Security

Russia, Iran pose most aggressive threat to 2024 elections, say infoseccers

April 25th 2024 at 13:34

Google security crew reveal β€˜the four Ds’ to be on the watch for

It may come as a surprise to absolutely nobody that experts say, in revealing the most prevalent and likely tactics to meddle with elections this year, that state-sponsored cybercriminals pose the biggest threat.…

☐ β˜† βœ‡ The Register - Security

What to do in the age of the critical breach

April 25th 2024 at 09:16

Why the triple threat of ransomware, data breaches, and extortion is a cybersecurity crisis

Webinar The UK government could be forgiven for wanting to forget March 2024 ever happened.…

☐ β˜† βœ‡ The Register - Security

Indian bank’s IT is so shabby it’s been banned from opening new accounts

April 25th 2024 at 06:29

After two years of warnings, and outages, regulators ran out of patience with Kotak Mahindra Bank

India’s central bank has banned Kotak Mahindra Bank from signing up new customers for accounts or credit cards through its online presence and app.…

☐ β˜† βœ‡ The Register - Security

Australia’s spies and cops want β€˜accountable encryption’ - aka access to backdoors

April 25th 2024 at 00:29

And warn that AI is already being used by extremists to plot attacks

The director general of Australia’s lead intelligence agency and the commissioner of its Federal Police yesterday both called for social networks to offer more assistance to help their investigators work on cases involving terrorism, child exploitation, and racist nationalism.…

☐ β˜† βœ‡ The Register - Security

Governments issue alerts after 'sophisticated' state-backed actor found exploiting flaws in Cisco security boxes

April 24th 2024 at 23:11

Don't get too comfortable: 'Line Dancer' malware may be targeting other vendors, too

A previously unknown and "sophisticated" nation-state group compromised Cisco firewalls as early as November 2023 for espionage purposes β€” and possibly attacked network devices made by other vendors including Microsoft, according to warnings from the networking giant and three Western governments.…

☐ β˜† βœ‡ The Register - Security

Shouldn't Teams, Zoom, Slack all interoperate securely for the Feds? Wyden is asking

April 24th 2024 at 19:43

Doctorow: 'The most amazing part is that this isn't already the way it's done'

Collaboration software used by federal government agencies β€” this includes apps from Microsoft, Zoom, Slack, and Google β€” will be required to work together and be securely end-to-end encrypted, if legislation proposed by US Senator Ron Wyden (D-OR) passes.…

☐ β˜† βœ‡ The Register - Security

Microsoft cannot keep its own security in order, so what hope for its add-ons customers?

April 24th 2024 at 17:15

Secure-by-default... if your pockets are deep enough

Microsoft has come under fire for charging for security add-ons despite the company's own patchy record when it comes to vulnerabilities and breaches.…

☐ β˜† βœ‡ The Register - Security

Management company settles for $18.4M after nuclear weapons plant staff fudged their timesheets

April 24th 2024 at 15:00

The firm 'fessed up to staff misconduct and avoided criminal liability

A company contracted to manage an Amarillo, Texas nuclear weapons facility has to pay US government $18.4 million in a settlement over allegations that its atomic technicians fudged their timesheets to collect more money from Uncle Sam.…

☐ β˜† βœ‡ The Register - Security

Google cools on cookie phase-out while regulators chew on plans

April 24th 2024 at 14:31

Privacy Sandbox slips into 2025 after challenges from UK authorities

Google's plan to phase out third-party cookies in Chrome is being postponed to 2025 amid wrangling with the UK's Competition and Markets Authority (CMA) and Information Commissioner's Office (ICO).…

☐ β˜† βœ‡ The Register - Security

US charges Iranians with cyber snooping on government, companies

April 24th 2024 at 14:01

Their holiday options are now far more restricted

The US has charged and sanctioned four Iranian nationals for their alleged roles in various attacks on US companies and government departments, all of whom are claimed to have worked for fake companies linked to Iran's military.…

☐ β˜† βœ‡ The Register - Security

If Britain is so bothered by China, why do these .gov.uk sites use Chinese ad brokers?

April 24th 2024 at 07:29

One wonders why are there adverts on public-sector portals at all

Exclusive At least 18 public-sector websites in the UK and US send visitor data in some form to various web advertising brokers – including an ad-tech biz in China involved in past privacy controversies, a security firm claims.…

☐ β˜† βœ‡ The Register - Security

Mandiant: Orgs are detecting cybercriminals faster than ever

April 23rd 2024 at 13:05

The 'big victory for the good guys' shouldn't be celebrated too much, though

The average time taken by global organizations to detect cyberattacks has dropped to its lowest-ever level of ten days, Mandiant revealed today.…

☐ β˜† βœ‡ The Register - Security

UnitedHealth admits IT security breach could 'cover substantial proportion of people in America'

April 23rd 2024 at 12:30

That said, good ol' American healthcare system so elaborately costly, some are forced to avoid altogether

UnitedHealth Group, the parent of ransomware-struck Change Healthcare, delivered some very unwelcome news for customers today as it continues to recover from the massively expensive side and disruptive digital break-in.…

☐ β˜† βœ‡ The Register - Security

Leicester streetlights take ransomware attack personally, shine on 24/7

April 23rd 2024 at 11:05

City council says it lost control after shutting down systems

It's become somewhat clichΓ© in cybersecurity reporting to speculate whether an organization will have the resources to "keep the lights on" after an attack. But the opposite turns out to be true with Leicester City Council following its March ransomware incident.…

☐ β˜† βœ‡ The Register - Security

Over a million Neighbourhood Watch members exposed through web app bug

April 23rd 2024 at 08:30

Unverified users could scoop up data on high-value individuals without any form of verification process

Neighbourhood Watch (NW) groups across the UK can now rest easy knowing the developers behind a communications platform fixed a web app bug that leaked their data en masse.…

☐ β˜† βœ‡ The Register - Security

Misconfigured cloud server leaked clues of North Korean animation scam

April 23rd 2024 at 05:26

Outsourcers outsourced work for the BBC, Amazon, and HBO Max to the hermit kingdom

A misconfigured cloud server that used a North Korean IP address has led to the discovery that film production studios including the BBC, Amazon, and HBO Max could be inadvertently using workers from the hermit kingdom for animation projects.…

☐ β˜† βœ‡ The Register - Security

Old Windows print spooler bug is latest target of Russia's Fancy Bear gang

April 23rd 2024 at 01:15

Putin's pals use 'GooseEgg' malware to launch attacks you can defeat with patches or deletion

Russian spies are exploiting a years-old Windows print spooler vulnerability and using a custom tool called GooseEgg to elevate privileges and steal credentials across compromised networks, according to Microsoft Threat Intelligence.…

☐ β˜† βœ‡ The Register - Security

FBI and friends get two more years of warrantless FISA Section 702 snooping

April 22nd 2024 at 21:09

Senate kills reform amendments, Biden swiftly signs bill into law

US lawmakers on Saturday reauthorized a contentious warrantless surveillance tool for another two years β€” and added a whole bunch of people and organizations to the list of those who can be compelled to spy for Uncle Sam.…

☐ β˜† βœ‡ The Register - Security

Europol now latest cops to beg Big Tech to ditch E2EE

April 22nd 2024 at 16:30

Don't bore us, get to the chorus: You need less privacy so we can protect the children

Yet another international cop shop has come out swinging against end-to-end encryption - this time it's Europol which is urging an end to implementation of the tech for fear police investigations will be hampered by protected DMs.…

☐ β˜† βœ‡ The Register - Security

Germany arrests trio accused of trying to smuggle naval military tech to China

April 22nd 2024 at 15:30

Prosecutors believe one frikkin' laser did make its way to Beijing

Germany has arrested three citizens who allegedly tried to transfer military technology to China, a violation of the country's export rules.…

☐ β˜† βœ‡ The Register - Security

Watchdog tells Dutch govt: 'Do not use Facebook if there is uncertainty about privacy'

April 22nd 2024 at 14:00

Meta insists it's just misunderstood and it's safe to talk to citizens over FB

The Dutch Data Protection Authority (AP) has warned that government organizations should not use Facebook to communicate with the country's citizens unless they can guarantee the privacy of data.…

❌