FreshRSS

πŸ”’
❌ Secure Planet Training Courses Updated For 2019 - Click Here
There are new available articles, click to refresh the page.
☐ β˜† βœ‡ The Register - Security

Utility security is so bad, US DoE offers rate cuts to improve it

β€” October 7th 2022 at 15:15

New hardware? Consultants? You tell us because your infosec is off the grid

The US Department of Energy has proposed regulations to financially reward cybersecurity modernization at power plants by offering rate deals for everything from buying new hardware to paying for outside help.…

☐ β˜† βœ‡ The Register - Security

China upgrades Great Firewall to defeat censor-beating TLS tools

β€” October 6th 2022 at 03:31

Just in time to ensure nobody can disagree that giving Xi five more years as president is the best idea ever

China appears to have upgraded its Great Firewall, the instrument of pervasive real-time censorship it uses to ensure that ideas its government doesn’t like don’t reach China’s citizens.…

☐ β˜† βœ‡ The Register - Security

Loads of PostgreSQL systems are sitting on the internet without SSL encryption

β€” October 7th 2022 at 10:48

They probably shouldn't be connected in the first place, says database expert

Only a third of PostgreSQL databases connected to the internet use SSL for encrypted messaging, according to a cloud database provider.…

☐ β˜† βœ‡ The Register - Security

Hardening data security in the cloud

β€” October 7th 2022 at 08:29

How Intel’s SGX hardware helps safeguard applications in multi-tenant environments

Sponsored Feature As enterprises continue to migrate applications into the cloud, security concerns about the data those workloads store and process are inevitable. But how can IT departments be certain that sensitive information covered by stringent data protection laws hosted in public, private and hybrid cloud environments spanning multiple servers and locations is adequately protected from both internal and external threats?…

☐ β˜† βœ‡ The Register - Security

South Korea cancels passport of Terraform Lab's Do Kwon

β€” October 6th 2022 at 16:02

Whereabouts of wanted cryptobro unknown, but he's reliably on Twitter

South Korea issued a publicly available notice on Wednesday to wanted man and Terraform Labs founder Do Kwon, demanding he return his passport.…

☐ β˜† βœ‡ The Register - Security

Top of the Pops: US authorities list the 20 hottest vulns that China's hackers love to hit

β€” October 7th 2022 at 05:28

Microsoft has four entries on list of shame, Log4j tops the chart

Three US national security agencies - CISA, the FBI and the NSA - on Thursday issued a joint advisory naming the 20 infosec exploited by state-sponsored Chinese threat actors since 2020.…

☐ β˜† βœ‡ The Register - Security

Lloyd's of London cuts off network after dodgy activity detected

β€” October 7th 2022 at 00:13

Is it Putin? Is it the Norks? Is it a bored teenager? Roll the dice

Updated Lloyd's of London has cut off its IT systems and is probing a possible cyberattack against it after detecting worrisome network behavior this week.…

☐ β˜† βœ‡ The Register - Security

Huge nonprofit hospital network suffers IT meltdown after 'security incident'

β€” October 6th 2022 at 21:55

Ambulances diverted, patient records frozen, rhymes with handsome wear

America's second-largest nonprofit healthcare org is suffering a security "issue" that has diverted ambulances and shut down electronic records systems at hospitals around the country.…

☐ β˜† βœ‡ The Register - Security

Papa John's sued for 'wiretap' spying on website mouse clicks, keystrokes

β€” October 6th 2022 at 20:20

When the tracking hits your eye like a big pizza pie, that's a priori

Papa John's is being sued by a customer – not for its pizza but for allegedly breaking the US Wiretap Act by snooping on the way he browsed the pie-slinger's website.…

☐ β˜† βœ‡ The Register - Security

Foreign spies hijacking US mid-terms? FBI, CISA are cool as cucumbers about it

β€” October 6th 2022 at 17:30

I think we can handle one little Russia. We sent two units, they're bringing any attempts down now

The FBI and the US government's Cybersecurity and Infrastructure Security Agency (CISA) claim any foreign interference in the 2022 US midterm elections is unlikely to disrupt or prevent voting, compromise ballot integrity, or manipulate votes at scale.…

☐ β˜† βœ‡ The Register - Security

Australian Federal Police arrest man suspected of exploiting Optus cyberattack

β€” October 6th 2022 at 12:30

Customers were allegedly sent texts demanding $1,300 or face having ID used in financial crime

Aussie police have cuffed a 19-year-old Sydney resident accused of trying to extort money from victims of the recent cyberattack and digital burglary at national telecommunications provider Optus.…

☐ β˜† βœ‡ The Register - Security

Learning from real life situations

β€” October 6th 2022 at 09:00

How about some cyber security education that’s actually delivered by people with genuine everyday experience?

Sponsored Post There's nothing much to be said in favour of cybercrime. It ruins legitimate endeavours and wrecks livelihoods. It does, though, build a sense togetherness among the people whose job is to stop it.…

☐ β˜† βœ‡ The Register - Security

Former Uber CSO convicted for covering up massive 2016 data theft

β€” October 6th 2022 at 00:33

Passing off a ransom payment as a bug bounty? That's obstruction of justice

Joe Sullivan, Uber's former chief security officer, has been found guilty of illegally covering up the theft of Uber drivers and customers' personal information.…

☐ β˜† βœ‡ The Register - Security

NetWalker ransomware scumbag jailed for 20 years

β€” October 5th 2022 at 22:54

And note to his crime pals – he said he would sing like a canary

An ex-Canadian government worker who extorted tens of millions of dollars from organizations worldwide using the NetWalker ransomware has been sent down for 20 years.…

☐ β˜† βœ‡ The Register - Security

Cyber-snoops broke into US military contractor, stole data, hid for months

β€” October 5th 2022 at 19:27

Tell us it’s Russia without telling us it’s Russia

Spies for months hid inside a US military contractor's enterprise network and stole sensitive data, according to a joint alert from the US government's Cybersecurity and Infrastructure Security Agency (CISA), the FBI, and NSA.…

☐ β˜† βœ‡ The Register - Security

Don’t let your employees become the weakest link

β€” October 5th 2022 at 12:59

Watch our webinar to learn the best way to keep data protected from human error

Webinar "You are the weakest link, goodbye!". One of the most famous catchphrases in television history. Popularized by the BBC gameshow and delivered by caustic TV presenter Anne Robinson, it is still the ultimate put down.…

☐ β˜† βœ‡ The Register - Security

Modified version of Tor Browser spies on Chinese users

β€” October 5th 2022 at 11:32

Patiently gathers data that can be used to identify the victims, says Kaspersky

Cybersecurity biz Kaspersky has spotted a modified version of the Tor Browser it says collects sensitive data on Chinese users.…

☐ β˜† βœ‡ The Register - Security

DoJ β€˜very disappointed’ with probation sentence for Capital One hacker Paige Thompson

β€” October 5th 2022 at 05:31

β€˜This is not what justice looks like’ says official on sanction for leak of 100 million records

Convicted wire fraud perpetrator Paige Thompson (aka "erratic") has been sentenced to time served and five years of probation with location and computer monitoring, prompting U.S. Attorney Nick Brown to label the sanctions unsatisfactory.…

☐ β˜† βœ‡ The Register - Security

All your identity needs fulfilled

β€” October 5th 2022 at 03:12

How to build an environment of trust and enhance customer experience

Video Digital transformation requires far-reaching and innovative business solutions, frequently tailormade.…

☐ β˜† βœ‡ The Register - Security

No Shangri-La for you: Top hotel chain confirms data leak

β€” October 5th 2022 at 02:15

In Xanadu did Kubla Khan a stately pleasure-dome decree

Hotel chain Shangri-La Group has admitted to its systems being attacked, and personal data describing guests accessed by unknown parties, over a timeframe that includes the dates on which a high-level international defence conference was staged at one of its Singapore properties.…

☐ β˜† βœ‡ The Register - Security

Uncle Sam orders federal agencies to step up scans for govt IT security holes

β€” October 4th 2022 at 22:26

Good time to be selling automation tools

The US government's Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal civilian agencies to scan for and report software vulnerabilities in their IT systems more frequently under a directive issued this week.…

☐ β˜† βœ‡ The Register - Security

Microsoft: Watch out for password spray attacks – especially you, Basic Auth

β€” October 4th 2022 at 16:15

Exchange Online users should have authentication policies in place

Microsoft is warning Exchange Online users about a rise in password spray attacks, urging those that have yet to disable Basic Authentication to at least set up authentication policies to protect their users and data.…

☐ β˜† βœ‡ The Register - Security

Japanese sushi chain boss resigns amid accusation of improper data access

β€” October 4th 2022 at 05:56

Data theft stinks, says victim. Alleged perp claims he's getting a raw deal

The president of casual Japanese chain restaurant Kappa Sushi resigned yesterday in the wake of a data-theft scandal that has rocked the world of sushi trains.…

☐ β˜† βœ‡ The Register - Security

Giveaways for every security professional

β€” October 4th 2022 at 03:00

Don’t chuck money away before you’ve checked SANS free educational content

Sponsored Post Fighting cybercrime is an expensive business. If your cyber defences fail, then the cost can be measured in many ways. There's the price of repairing damaged infrastructure, retrieving lost data, and paying regulatory penalties. And the cost in reputational terms with customers simply has no metric.…

☐ β˜† βœ‡ The Register - Security

Atlassian, Microsoft bugs on CISA’s must-patch list after exploitation spree

β€” October 4th 2022 at 00:31

Some days, security just feels like a total illusion. OK, most days...

A recently disclosed critical vulnerability in Atlassian's Bitbucket is actively being exploited, according to the US government.…

☐ β˜† βœ‡ The Register - Security

Online romance scamlord who netted $9.5m jailed for 25 years

β€” October 3rd 2022 at 22:15

Hello, love, I need $32k to fix my oil rig

A man in the US has been jailed for 25 years after using dating websites, email scams, and other online swindles to steal more than $9.5 million from companies and individuals.…

☐ β˜† βœ‡ The Register - Security

From today, America and UK follow new rules on how they can demand your data from each other

β€” October 3rd 2022 at 19:11

Cops and Feds get easier info sharing, Britain benefits most

The Data Access Agreement (DAA), by which the US and UK have agreed how one country can respond to lawful data demands from police and investigators in the other, took effect on Monday.…

☐ β˜† βœ‡ The Register - Security

It's 2058. A quantum computer is just another decade away. Still, you curse Cloudflare

β€” October 3rd 2022 at 18:22

Assuming this Kyber TLS stuff works as expected

Cloudflare is the first major internet infrastructure provider to support post-quantum cryptography for all customers, which, in theory, should protect data if quantum computing ever manages to break today's encryption technologies.…

☐ β˜† βœ‡ The Register - Security

National Cybersecurity Awareness program 18 years on: Don't click that

β€” October 3rd 2022 at 17:30

Technology is addressing many of the cyberthreats, but the human element will always be a factor

If you've ever found yourself in an interminable meeting listening to the CISO ramble on about the important role you play in protecting yourself and the company from cyberthreats, you could probably point an accusatory finger in large part at the National Cybersecurity Awareness Month (NCSAM) program.…

☐ β˜† βœ‡ The Register - Security

FBI: We tracked who was printing secret documents to unmask ex-NSA suspect

β€” October 3rd 2022 at 17:00

Infosec systems designer alleged to have chatted with undercover agent

A 30-year-old ex-NSA employee was accused by the FBI of trying to sell classified US information to a foreign government – after the Feds said they linked him to the printing of secret documents.…

☐ β˜† βœ‡ The Register - Security

Cyber-proofing data in the cloud

β€” October 3rd 2022 at 13:24

How to reduce the risk and impact of ransomware attacks on AWS data and applications

Webinar Ransomware has a longer history than you might imagine. The very first recognized attack was at the World Health Organization in 1989 when the AIDS Trojan was distributed to 20,000 attendees via floppy disc.…

☐ β˜† βœ‡ The Register - Security

Founder of cybersecurity firm Acronis is afraid of his own vacuum cleaner

β€” October 3rd 2022 at 10:46

It is the exponential changes in the course of human history that worry Serg Bell

Acronis founder Serg Bell is afraid of his own vacuum cleaner, he told The Register in Singapore last week.…

☐ β˜† βœ‡ The Register - Security

Between ransomware and month-long engagements, IR teams need a hug – and a nap

β€” October 3rd 2022 at 10:00

Here's what 1,100 incident responders say about their jobs, just in time for NSCAM

Remember the good old days of cyber-incident response, when the job involved digital forensics and lots of stolen credit cards, as opposed to power-grid-breaking malware and multi-million-dollar ransom demands?…

☐ β˜† βœ‡ The Register - Security

Moody's turns up the heat on 'riskiest' sectors for cyberattacks

β€” October 3rd 2022 at 06:33

$22 trillion of global rated debt has 'high' or 'very high' cyber-risk exposure

About $22 trillion of global debt rated by Moody's Investors Service has "high," or "very high" cyber-risk exposure, with electric, gas and water utilities, as well as hospitals, among the sectors facing the highest risk of cyberattacks.…

☐ β˜† βœ‡ The Register - Security

Steganography alert: Backdoor spyware stashed in Microsoft logo

β€” October 2nd 2022 at 12:56

Now that's sticker shock

Internet snoops have been caught concealing spyware in an old Windows logo in an attack on governments in the Middle East.…

☐ β˜† βœ‡ The Register - Security

BlackCat malware lashes out at US defense IT contractor

β€” October 2nd 2022 at 08:47

Also, Amazon's Ring footage TV shows draws criticism, US v Soviet spying docs found, and more

In Brief The BlackCat ransomware gang, also known as ALPHV, has allegedly broken into IT firm NJVC, a provider of services to civilian US government agencies and the Department of Defense.…

☐ β˜† βœ‡ The Register - Security

Gone in a day: Ethical hackers say it would take mere hours to empty your network

β€” October 1st 2022 at 09:57

300 red teamers walk into a bar…

Once they've broken into an IT environment, most intruders need less than five hours to collect and steal sensitive data, according to a SANS Institute survey of more than 300 ethical hackers. …

☐ β˜† βœ‡ The Register - Security

Microsoft warns of North Korean crew posing as LinkedIn recruiters

β€” September 30th 2022 at 05:53

State-sponsored ZINC allegedly passes on malware-laden open source apps

Microsoft has claimed a North Korean crew poses as LinkedIn recruiters to distribute poisoned versions of open source software packages.…

☐ β˜† βœ‡ The Register - Security

Stop us if you've heard this one before: Exchange Server zero-days actively exploited

β€” September 30th 2022 at 03:03

Remember this next time Microsoft talks about how seriously it takes security

Updated Infosec experts have warned zero-day flaws in Microsoft’s Exchange server are being actively exploited.…

☐ β˜† βœ‡ The Register - Security

Ex-eBay execs jailed for cyberstalking web critics

β€” September 30th 2022 at 00:58

Still to come: Civil RICO lawsuit against e-souk and former top brass

Two now-former eBay executives who pleaded guilty to cyberstalking charges this year have been sent down and fined tens of thousands of dollars.…

☐ β˜† βœ‡ The Register - Security

How CIA betrayed informants with shoddy front websites built for covert comms

β€” September 29th 2022 at 23:03

Top tip, don't give your secret login box the HTML form type 'password'

For almost a decade, the US Central Intelligence Agency communicated with informants abroad using a network of websites with hidden communications capabilities.…

☐ β˜† βœ‡ The Register - Security

Pentagon is far too tight with its security bug bounties

β€” September 29th 2022 at 21:27

But overpriced, useless fighter jets? That's something we can get behind

Discovering and reporting critical security flaws that could allow foreign spies to steal sensitive US government data or launch cyberattacks via the Department of Defense's IT systems doesn't carry a high reward.…

☐ β˜† βœ‡ The Register - Security

Covert malware targets VMware shops for hypervisor-level espionage

β€” September 29th 2022 at 13:00

Mandiant tracks back operators, finds ties to China

Emerging covert malware can target VMware environments to allow criminals to gain persistent administrative access to hypervisors, transfer files, and execute arbitrary commands on virtual machines, according to VMware and Mandiant, which discovered such a software nasty in the wild earlier this year.…

☐ β˜† βœ‡ The Register - Security

Microsoft to kill off old access rules in Exchange Online

β€” September 28th 2022 at 23:34

Awoooogah – this is your one-year warning to switch over, enterprises

Microsoft next month will start phasing out Client Access Rules (CARs) in Exchange Online – and will do away with this means for controlling access altogether within a year.…

☐ β˜† βœ‡ The Register - Security

Matrix chat encryption sunk by five now-patched holes

β€” September 28th 2022 at 21:22

You take the green pill, you'll spend six hours in a 'don't roll your own crypto' debate

Four security researchers have identified five cryptographic vulnerabilities in code libraries that can be exploited to undermine Matrix encrypted chat clients. This includes impersonating users and sending messages as them.…

☐ β˜† βœ‡ The Register - Security

The web's cruising at 13 million new and nefarious domain names a month

β€” September 28th 2022 at 20:20

Or so Akamai is dying to tell us

Akamai reckons that, in the first half of 2022 alone, it flagged nearly 79 million newly observed domains (NODs) as malicious.…

☐ β˜† βœ‡ The Register - Security

Want to sneak a RAT into Windows? Buy Quantum Builder on the dark web

β€” September 28th 2022 at 17:00

Beware what could be hiding in those LNK shortcuts

A tool sold on the dark web that allows cybercriminals to build malicious shortcuts for delivering malware is being used in a campaign pushing a longtime .NET keylogger and remote access trojan (RAT) named Agent Tesla.…

☐ β˜† βœ‡ The Register - Security

Hacked Fast Company sends 'obscene and racist' alerts via Apple News

β€” September 28th 2022 at 16:30

Someone going by 'Thrax' claims responsibility for 'incredibly easy' breach

Apple News shut down Fast Company's news channel after "an incredibly offensive alert" was sent to subscribers following a hack of the business publication on Tuesday evening.…

☐ β˜† βœ‡ The Register - Security

Reducing the risk of human error in cyber security

β€” September 28th 2022 at 13:56

Tips on how to turn a potential weakness into a towering strength

Webinar We all make mistakes. Some happy accidents enhance the way we live. Matches were invented when scientist John Walker was cleaning his laboratory with a wooden stick coated in chemicals and it caught fire. But if you are trying to secure your data, unforced errors are the last thing you need to torch it.…

☐ β˜† βœ‡ The Register - Security

Ever suspected bankers could just use WhatsApp comms? $1.8b says you're right

β€” September 28th 2022 at 13:00

Thought shadow IT at your office was bad? Try enforcing workplace device policies on hedge fund traders

Updated Ever given a colleague a quick Signal call so you can sidestep a monitored workplace app? Well, we'd hope you're not in a highly regulated industry like staff at eleven of the world's most powerful financial firms, who yesterday were fined nearly $2 billion for off-channel comms.…

☐ β˜† βœ‡ The Register - Security

Here's how crooks will use deepfakes to scam your biz

β€” September 28th 2022 at 07:24

Need some tools of deception? GitHub's got 'em

All of the materials and tools needed to make deepfake videos – from source code to publicly available images and account authentication bypass services – are readily available and up for sale on the public internet and underground forums. …

☐ β˜† βœ‡ The Register - Security

Australia asks FBI to help find attacker who stole data from millions of users

β€” September 28th 2022 at 03:35

Apparent perp claims to have deleted swiped info as carrier Optus struggles to get its story straight

+Comment Australian authorities have asked the United States Federal Bureau of Investigation (FBI) to assist with investigations into the data breach at local telco Optus.…

☐ β˜† βœ‡ The Register - Security

A question of identity

β€” September 28th 2022 at 03:09

How Incode creates trust by keeping data private and secure

Video There's no getting away from it, identity is key - the prima materia for creating security and trust in your multi-cloud universe.…

☐ β˜† βœ‡ The Register - Security

Sophos fixes critical firewall hole exploited by miscreants

β€” September 28th 2022 at 00:35

Code-injection bug in your network security... mmm, yum yum

A critical code-injection vulnerability in Sophos Firewall has been fixed β€”Β but not before miscreants found and exploited the bug.…

☐ β˜† βœ‡ The Register - Security

Samsung sued for gobbling up too much personal info that miscreants then stole

β€” September 27th 2022 at 18:15

If you're gonna force everyone to register an account, at least protect that data, lawsuit argues

A lawsuit has accused Samsung of failing to address a cyber-intrusion in early 2022, leading to the theft of US customers' personally identifiable information (PII) in a second attack months later in July.…

☐ β˜† βœ‡ The Register - Security

Meta busts first Chinese campaign prodding US midterms

β€” September 27th 2022 at 15:00

Russian cybercriminals were also caught targeting Europe with anti-Ukraine messages

Meta says it has disrupted a misinformation network targeting US political discourse ahead of the 2022 midterm elections – and one that sought to influence public opinion in Europe about the conflict in Ukraine.…

☐ β˜† βœ‡ The Register - Security

Microsoft says it's boosted phishing protection in Windows 11 22H2

β€” September 27th 2022 at 14:00

Security tool warns admins, users when a password is used on an untrusted site or stored locally

In the latest version of Windows 11, namely 22H2, Microsoft has introduced a feature in its Defender SmartScreen tool designed to, hopefully, keep passwords safer.…

☐ β˜† βœ‡ The Register - Security

What's Microsoft been up to? A quick tour of Windows 11 22H2's security features

β€” September 27th 2022 at 11:32

And some requirements to be aware of

In brief As it rolled out a laundry list of features in the latest version of Windows 11, namely version 22H2, this month, Microsoft has also detailed some of the added security mechanisms.…

☐ β˜† βœ‡ The Register - Security

China's infosec researchers obeyed Beijing and stopped reporting vulns ... or did they?

β€” September 27th 2022 at 06:58

Report finds increase in anonymous vuln reports

The number of vulnerability reports provided by Chinese information security researchers has fallen sharply, according to research by think tank The Atlantic Council, which also found a strangely commensurate increase in bug reports from unknown sources.…

☐ β˜† βœ‡ The Register - Security

Ukraine fears 'massive' Russian cyberattacks on power, infrastructure

β€” September 27th 2022 at 00:03

Will those be before or after the nuke strikes Putin keeps banging on about?

Russia plans to conduct "massive cyberattacks" on Ukraine and its allies' critical infrastructure and energy sector, according to Kyiv.…

❌