FreshRSS

πŸ”’
❌ Secure Planet Training Courses Updated For 2019 - Click Here
There are new available articles, click to refresh the page.
Before yesterdayThe Register - Security

Learn the art of malicious compliance: doing exactly what you were asked, even when it's wrong

Smart-alec worker found a way to avoid nasty, boring jobs – by doing what he was told

Who, Me? Ah, gentle reader, welcome back once again to the comfortable backwater of The Register we call Who, Me? in which readers' tales of not-quite-rightness are immortalized for the ages.…

China's spy balloon barrage earns six of its companies a spot on US entity list

US Commerce Department can't just let red balloons go by

The US Department of Commerce added six more entities to its blacklist on Friday on grounds of national security after an errant Chinese surveillance balloon was shot down over the US last week.…

Ransomware crooks steal 3m+ patients' medical records, personal info

All that data coming soon to a darkweb crime forum near you?

Several California medical groups have sent security breach notification letters to more than three million patients alerting them that crooks may have stolen a ton of their sensitive health and personal information during a ransomware infection in December.…

US, UK slap sanctions on Russians linked to Conti, Ryuk, Trickbot malware

Any act that sends so much as a ruble to seven named netizens now forbidden

The US and UK have sanctioned seven Russians for their alleged roles in disseminating Conti and Ryuk ransomware and the Trickbot banking trojan.…

US teases more China tech sanctions, this time to deflate balloon-makers

State Dept already has one target, FBI is identifying sources of floating surveillance platform's components

The Chinese surveillance balloon that drifted across the US last week looks set to spark a new round of sanctions against Middle Kingdom tech firms.…

Australia gives made-in-China CCTV cams the boot

The usual suspects - Hikvision and Dahua - named as a risk to national security, prompting the usual denials

Australia's Defence Department removed all Chinese manufactured surveillance cameras after an audit detailed the number of Hikvision and Dahua devices installed in various government facilities.…

Romance scammers' favorite lies cost victims $1.3B last year

Don't trust your super-hot military boyfriend you've never met. He doesn't exist

As Valentine's Day approaches, if your offshore oil rig worker "boyfriend" – who looks like Bradley Cooper in his online pics and has hinted at proposing to you for months, but you've never met in real life – suddenly needs money for "hospital bills" … Just. Don't. Do. It.…

Reddit reveals security incident that looks more SNAFU than TIFU

Phishing hooked internal documents, code, and some non-critical systems, but users' personal info safe

Colorful web forum Reddit has revealed it has suffered a security breach.…

Codebreakers decipher Mary, Queen of Scots' secret letters 436 years after her execution

Digital sleuths chop through crypto challenge in 'surreal' search

A team of codebreakers discovered – and then cracked – more than 50 secret letters written by Mary Stuart, Queen of Scots while she was imprisoned in England by her cousin, Queen Elizabeth I. …

Uncle Sam wants to strip the IoS out of IoT with light crypto

NIST weighs up algorithms for small devices – and an architecture for massive systems

The US National Institute of Standards and Technology wants to protect all devices great and small, and is getting closer to settling on next-gen cryptographic algorithms suitable for systems at both ends of that spectrum – the very great and the very small.…

Among the thousands of ESXiArgs ransomware victims? FBI and CISA to the rescue

Evil code hits more than 3,800 servers globally, according to the Feds

The US Cybersecurity and Infrastructure Security Agency (CISA) has released a recovery script to help companies whose servers were scrambled in the recent ESXiArgs ransomware outbreak.…

Scammers steal $4 million in crypto during face-to-face meeting

Demand to display wallet full of coin facilitated mystery heist

Ahad Shams, the co-founder of Web3 metaverse gaming engine startup Webaverse, discovered in late November 2022 that someone had stolen $4 million of his cryptocurrency – during a real world interaction.…

Suspect in Finnish psychotherapy center blackmail hack arrested

Suomi sentence expected for shrink records theft

French police have arrested a 25-year-old Finnish man accused of hacking a psychotherapy clinic, stealing more than 22,000 patients' therapy notes, demanding ransom payments from them and also leaking this very private info on a Tor website.…

Eurocops shut down Exclu encrypted messaging app, arrest dozens

German and Dutch authorities say the app was a favorite of organized criminals and drug smugglers

An encrypted messaging service that has been on law enforcement's radar since a 2019 raid on an old NATO bunker has been shut down after a sweeping series of raids across Europe last week. …

Embarrassment as US cyber ambassador's Twitter account is hacked

'Perils of the job' we're told

A top US cyber diplomat said his Twitter account was compromised over the weekend.…

Here's a list of proxy IPs to help block KillNet's DDoS bots

Put pro-Putin bots on the do not call list

A free tool aims is helping organizations defend against KillNet distributed-denial-of-service (DDoS) bots and comes as the US government issued a warning that the Russian cybercrime gang is stepping up its network flooding attacks against hospitals and health clinics.…

Keeping unstructured data safe and sound

How Dell PowerScale helps defend against information breaches

Webinar There was a time when data was stored in cardboard files inside metal filing cabinets. The drawers were locked with a little key in the corner of the cabinet, which generally meant there was no getting in unless you had that key or at least some time to spare with a crowbar.…

Trust, not tech, is holding back a safer internet

Excuse me, citizen, did you packet this data yourself?

Opinion The tech sector is failing at cybersecurity. Global spending on the stuff is at $190 billion a year, a quarter of the US defense budget. That hasn't stemmed an estimated $7 trillion in annual cybercriminal damages. People are fond of saying that the Wild West days of the internet are over, but on those numbers an 1875 Dodge City bank vault looks like Fort Knox.…

School laptop auction devolves into extortion allegation

Also: Atlassian says Jira has a 9.4 severity bug and the TSA issues milquetoast no-fly list security advisory

When a Texas school district sold some old laptops at auction last year, it probably didn't expect to end up in a public legal fight with a local computer repair shop – but a debate over what to do with district data found on the liquidated machines has led to precisely that.…

Ransomware scum launch wave of attacks on critical, but old, VMWare ESXi vuln

You’ve had almost two years to patch and some of the software is EOL, now attackers dΓ©ployer un ranΓ§ongiciel

France's Computer Emergency Response Team has issued a Bulletin D'Alerte regarding a campaign to infect VMware’s ESXI hypervisor with ransomware.…

Have we learnt nothing from SolarWinds supply chain attacks? Not yet it appears

From frameworks to new federal offices it's time to get busy

The hack of SolarWinds' software more than two years ago pushed the threat of software supply chain attacks to the front of security conversations, but is anything being done?.…

Iran crew stole Charlie Hebdo database, says Microsoft

Same gang pestered US voters during 2020 presidential election

Microsoft believes the gang who boasted it had stolen and leaked more than 200,000 Charlie Hebdo subscribers' personal information is none other than a Tehran-backed criminal group.…

HeadCrab bots pinch 1,000+ Redis servers to mine coins

We devoting full time to floating under /etc

A sneaky botnet dubbed HeadCrab that uses bespoke malware to mine for Monero has infected at least 1,200 Redis servers in the last 18 months.…

Fast-evolving Prilex POS malware can block contactless payments

... forcing users to insert their cards into less-secure PIN systems

The reasons businesses and consumers like contactless payment transactions – high security and speed – are what make those systems bad for cybercriminals.…

Guy accused of wrecking crypto exchange now hauled into court

Mango Markets still offline for now ... but v4 comeback release looms

The man accused of bringing down decentralized crypto exchange Mango Markets through market manipulation has made his first appearance in court in connection with the theft of millions in cryptocurrency.…

Chinese surveillance balloon over US causes fearful gasbagging

Floats over missile silos, shooting it down ruled more dangerous than whatever it's up to

Updated A Chinese high-altitude spy balloon, spotted drifting over America, has caused concern about national security – though the US Department of Defense says it will not be shot down by F22s at this time.…

Another RAC staffer nabbed for storing, sharing car crash data

Once is an accident. Twice is coincidence. Surely there won't be a third for roadside assistance biz

A former employee of RAC, one of Britain's major roadside recovery service operators, has pleaded guilty to data theft after he stored traffic accident information on his personal device that was passed onto claims companies.…

LockBit brags it pumped ION full of ransomware

Crims put a February 4 deadline for software slinger to pay up

UK regulators are investigating a cyberattack against financial technology firm ION, while the LockBit ransomware gang has threatened to publish the stolen data on February 4 if the software provider doesn't pay up.…

Former Ubiquiti dev pleads guilty in data theft and extortion case

Nickolas Sharp now faces up to 35 years in prison

A former Ubiquiti Networks employee accused of hatching an elaborate plot to first steal nearly $2 million from his employer, extort more, then later orchestrating a smear campaign against the company pleaded guilty to multiple felony charges Thursday.…

Malvertising attacks are distributing .NET malware loaders

The campaign illustrates another option for miscreants who had relied on Microsoft macros

Malvertising attacks are being used to distribute virtualized .NET loaders that are highly obfuscated and dropping info-stealer malware.…

Super Bock says 'cyber' nasty 'disrupting computer services'

Portugal's biggest exporter of beer warns of restrictions to supply chain

Super Bock Group, Portugal's largest beverage biz, is warning of potential interruption to supplies as it manages the fallout from cybercrooks attacking its tech infrastructure.…

Google boosts bounties for open source flaws found via fuzzing

Max reward per project integration is now $30k

Google sweetened the potential pot to $30,000 for bug hunters in its open source OSS-Fuzz code testing project.…

Microsoft sweeps up after breaking .NET with December security updates

XPS doc display issues fixed – until the next patch, at least

Microsoft this week rolled out fixes to issues caused by security updates released in December 2022 that botched how XPS documents are displayed in various versions of .NET and .NET Framework.…

Attackers abuse Microsoft’s 'verified publisher' status to steal data

Malicious OAuth apps were the tickets into victims' systems

Miscreants using malicious OAuth applications abused Microsoft's "verified publisher" status to gain access to organizations' cloud environments, then steal data and pry into to users' mailboxes, calendars, and meetings.…

Microsoft upgrades Defender to lock down Linux gear for its own good

Ballmer thought this kernel was cancer, Nadella may disagree

Organizations using Microsoft's Defender for Endpoint will now be able to isolate Linux devices from their networks to contain intrusions and whatnot.…

New year, new storage challenge

How to keep unstructured data secure

Webinar If your IT team is making new year resolutions, one of them might be to ramp up safeguarding measures for the increasing amount of unstructured data being captured by businesses and organizations.…

Amid FTX's burning wreckage, Japan outpost promises asset withdrawals in February

Well what do you know – plenty of hard-nosed regulation by central authorities actually protected investors

Collapsed crypto exchange FTX's Japanese outpost has told customers it will permit them to withdraw assets in February.…

South Korea makes crypto crackdown a national justice priority

It's listed alongside issues like tackling gang violence, drugs, and sex crimes

South Korea's Ministry of Justice will create a "Virtual Currency Tracking System" to crack down on money laundering facilitated by cryptocurrencies, and rated the establishment of the facility among its priorities for the year.…

Chromebook SH1MMER exploit promises admin jailbreak

Schools' laptops are out if this one gets around, tho beware bricking

Users of enterprise-managed Chromebooks now, for better or worse, have a way to break the shackles of administrative control through an exploit called SHI1MMER.…

The wages of sin aren't that great if you're a developer choosing the dark side

Salary report shows OKish pay, plus the possibility of getting ripped off and the whole prison thing

Malware developers and penetration testers are in high demand across dark web job posting sites, with a few astonishing - but mostly average - wages.…

Gootloader malware updated with PowerShell, sneaky JavaScript

Perhaps a good time to check for unwelcome visitors

The operators of the Windows Gootloader malware – a crew dubbed UNC2565 – have upgraded the code in cunning ways to make it more intrusive and harder to find.…

JD Sports admits intruder accessed 10 million customers' data

No payment details exposed in breach, says retailer, but shoppers told to be 'vigilant about potential scams'

Sports fashion retailer JD Sports has confirmed miscreants broke into a system that contained data on a whopping 10 million customers, but no payment information was among the mix.…

We are the weakest link

Mitigating the risks of human error in digital defenses

Webinar It's a startling truth but 45 percent of workers in the US believe using public Wi-Fi is safe.…

Gee, tanks: Russian hackers DDoS Germany for aiding Ukraine

Also: a week of leaks; Riot Games says 'LoL' to source code ransom demands; and Yandex source also appears online

in brief Russian hackers have proved yet again how quickly cyber attacks can be used to respond to global events with a series of DDoS attacks on German infrastructure and government websites in response to the country's plan to send tanks to Ukraine.…

Mon Dieu! Suspected French ShinyHunters gang member in the dock

Man seized in Morocco is now presumably sleepless in Seattle

A French citizen was scheduled to appear before a US court on Friday on a nine-count indictment related to his alleged involvement in the ShinyHunters cybercrime gang that trafficked in identity and corporate data theft and sometimes extortion.…

Microsoft to enterprises: Patch your Exchange servers

If you want to keep the miscreants out, put the updates in, Redmond says

Microsoft is urging organizations to protect their Exchange servers from cyberattacks by keeping them updated and hardened, since online criminals are still going after valuable data in the email system.…

Uncle Sam slaps $10m bounty on Hive while Russia ban-hammers FBI, CIA

New meaning to sweetening the pot

Uncle Sam has put up a $10 million reward for intel on Hive ransomware criminals' identities and whereabouts, while Russia has blocked the FBI and CIA websites, along with the Rewards for Justice site offering the bounty.…

FBI smokes ransomware Hive after secretly buzzing around gang's network for months

Uncle Sam doles out decryption keys to 300+ victims amid sting op

The FBI said it has shut down the Hive's ransomware network, seizing control of the notorious gang's servers and websites, and thwarting the pesky criminals' ability to sting future victims.…

FBI catches up with infosec and crypto communities, blames Lazarus Group for $100 million heist

Well played, feds. What's next? Ransomware is rampant? Strong passwords are important?

The FBI has confirmed what cybersecurity researchers have been saying for months: the North Korean-sponsored Lazarus Group was behind the theft last year of $100 million in crypto assets from blockchain startup Harmony.…

Savvy cybersecurity pros benefit from host of free resources to step up fight against hackers and cyber threats

Sign up to SANS Institute to keep up to speed with all aspects of the fast-evolving infosec sector

Sponsored Post They say there's no such thing as a free lunch, but in fact there's a veritable feast of valuable resources online for infosec professionals which won't cost you anything.…

UK Cyber Security Centre's scary new story: One phish, two phish, Russia phish, Iran phish

Nice people on LinkedIn want to harvest logins from politicians, boffins, and defense types

The UK's National Cyber Security Centre (NCSC) has warned of two similar spear-phishing campaigns, one originating from Russia, the other from Iran.…

Google slays thousands of fake news vids posted by pro-China group Dragonbridge

If you yell 'death to America' and no one watches the video, does it make a sound?

Google's Threat Analysis Group (TAG) has burned more than 50,000 spammy fake news stories and other content posted by the pro-China 'Dragonbridge' gang.…

Bloke allegedly stole, sold private info belonging to 'tens of millions' globally

If true, was it worth the $500k and prison jumpsuit?

A man suspected of stealing personal data belonging to tens of millions of people worldwide and selling that info on cybercrime forums has been arrested by Dutch police.…

Months after NSA disclosed Microsoft cert bug, datacenters remain unpatched

You know when we all said quit using MD5? We really meant it

Most Windows-powered datacenter systems and applications remain vulnerable to a spoofing bug in CryptoAPI that was disclosed by the NSA and the UK National Cyber Security Center (NCSC) and patched by Microsoft last year, according to Akamai's researchers.…

Microsoft closes another door to attackers by blocking Excel XLL files from the internet

More of them used by baddies since Redmond blocked VBA macros

Microsoft in March will start blocking Excel XLL add-ins from the internet to shut down an increasingly popular attack vector for miscreants.…

Strengthening the human element

How to locate cybersecurity risks in remote working

Webinar The implementation of lockdowns during the maelstrom of the Coronavirus pandemic led to fast track changes to traditional work practices. To meet the challenges of operating in a global emergency, businesses and organizations of every kind had to urgently find a way to keep operating.…

Cybersecurity professionals upskill in Brazil and Mexico

SANS Institute meets fast-growing demand for cyber security training in Latin America

Sponsored Post The scale of cybersecurity threats facing Latin America was brought into focus by recently when it published details of NICKEL, a "China-based threat actor". The malware was used to attack global organisations with "a large amount of activity" targeting Central and South America, including Mexico and Brazil.…

Go to security school, GoTo – theft of encryption keys shows you need it

Ongoing probe into cloud storage attack finds customer data exfiltrated

Remote access outfit GoTo has admitted that a threat actor exfiltrated an encryption key that allowed access to "a portion" of encrypted backup files.…

Logfile management is no fun. Now it's a nightmare thanks to critical-rated VMware flaws

You know the drill: patch before criminals use these bugs in vRealize to sniff your systems

VMware has issued fixes for four vulnerabilities, including two critical 9.8-rated remote code execution bugs, in its vRealize Log Insight software. …

Apple emits emergency patch for older iPhones after snoops pounce on WebKit hole

Also: Yay for Data Privacy Day!

Apple has issued an emergency patch for older kit to fix a WebKit security flaw that Cupertino warns is under active attack.…

❌