FreshRSS

πŸ”’
❌ Secure Planet Training Courses Updated For 2019 - Click Here
There are new available articles, click to refresh the page.
☐ β˜† βœ‡ The Register - Security

If you're using Polyfill.io code on your site – like 100,000+ are – remove it immediately

β€” June 25th 2024 at 23:48

Scripts turn malicious, infect webpages after Chinese CDN swallows domain

The polyfill.io domain is being used to infect more than 100,000 websites with malware after a Chinese organization bought the domain earlier this year.…

☐ β˜† βœ‡ The Register - Security

Fiend touts stolen Neiman Marcus customer info for $150K

β€” June 25th 2024 at 20:27

Flash clobber chain fashionably late to Snowflake fiasco party

Customer information said to have been stolen from Neiman Marcus's Snowflake instance has been put up for sale on the dark web for $150,000.…

☐ β˜† βœ‡ The Register - Security

Crypto scammers circle back, pose as lawyers, steal an extra $10M in truly devious plan

β€” June 25th 2024 at 18:28

Business is more lucrative than you might think

The FBI says in just 12 months, scumbags stole circa $10 million from victims of crypto scams after posing as helpful lawyers offering to recover their lost tokens.…

☐ β˜† βœ‡ The Register - Security

CISA says crooks used Ivanti bugs to snoop around high-risk chemical facilities

β€” June 25th 2024 at 13:45

Crafty crims broke in but encryption stopped any nastiness

US cybersecurity agency CISA is urging high-risk chemical facilities to secure their online accounts after someone broke into its Chemical Security Assessment Tool (CSAT) portal.…

☐ β˜† βœ‡ The Register - Security

UK and US cops band together to tackle Qilin's ransomware shakedowns

β€” June 25th 2024 at 12:01

Attacking the NHS is a very bad move

UK and US cops have reportedly joined forces to find and fight Qilin, the ransomware gang wreaking havoc on the global healthcare industry.…

☐ β˜† βœ‡ The Register - Security

Ransomware thieves beware

β€” June 25th 2024 at 09:12

Why Object First and Veeam tick the box for encryption and immutability

Sponsored Feature You know that a technology problem is serious when the White House holds a summit about it.…

☐ β˜† βœ‡ The Register - Security

Protect your network

β€” June 25th 2024 at 09:00

Insights on expanding attack surfaces

Webinar Stay ahead of cyber threats with our upcoming session on "Why attack surfaces are expanding," brought to you by Cloudflare in partnership with The Register.…

☐ β˜† βœ‡ The Register - Security

Julian Assange to go free in guilty plea deal with US

β€” June 25th 2024 at 00:19

WikiLeaks boss already out of Blighty and, if all goes to plan, ultimately off to home in Australia

WikiLeaks founder Julian Assange has been freed from prison in the UK after agreeing to plead guilty to just one count of conspiracy to obtain and disclose national defense information, brought against him by the United States. Uncle Sam previously filed more than a dozen counts.…

☐ β˜† βœ‡ The Register - Security

America's best chance for nationwide privacy law could do more harm than good

β€” June 25th 2024 at 00:02

'Congress has effectively gutted it as part of a backroom deal'

Analysis Introduced in April, the American Privacy Rights Act (APRA) was - in the words of its drafters - "the best opportunity we’ve had in decades to establish a national data privacy and security standard that gives people the right to control their personal information."…

☐ β˜† βœ‡ The Register - Security

Ollama drama as 'easy-to-exploit' critical flaw found in open source AI server

β€” June 24th 2024 at 20:34

About a thousand vulnerable instances still exposed online, we're told

A now-patched vulnerability in Ollama – a popular open source project for running LLMs – can lead to remote code execution, according to flaw finders who warned that upwards of 1,000 vulnerable instances remain exposed to the internet.…

☐ β˜† βœ‡ The Register - Security

Car dealers stuck in the slow lane after cyber woes at software biz CDK

β€” June 24th 2024 at 18:02

More customers self-reporting to SEC as disruption carries into second week

The number of US companies filing Form 8-Ks with the Securities and Exchange Commission (SEC) and referencing embattled car dealership software biz CDK is mounting.…

☐ β˜† βœ‡ The Register - Security

'Mirai-like' botnet observed attacking EOL Zyxel NAS devices

β€” June 24th 2024 at 14:39

Seems like as good a time as any to upgrade older hardware

There are early indications of active attacks targeting end-of-life Zyxel NAS boxes just a few weeks after details of three critical vulnerabilities were made public.…

☐ β˜† βœ‡ The Register - Security

Britain's Ministry of Defence accused of wasting Β£174M on 'external advice'

β€” June 24th 2024 at 12:50

Morpheus comms system online by 2025? You must be dreaming

The UK government has been accused of blowing Β£174 million ($220 million) on "external advice" for a new radio system for the armed forces that has been beset by delays and cancelled contracts.…

☐ β˜† βœ‡ The Register - Security

Levi's and more affected in pants-dropping week of data breaches

β€” June 24th 2024 at 10:34

A busy few days for security teams

There were data breaches galore in the US last week with various major incidents reported to state attorneys general, some in good time, some not.…

☐ β˜† βœ‡ The Register - Security

Meta, Microsoft SQL Server make strange bedfellows on a couch of cyber-pain

β€” June 24th 2024 at 08:30

Yanks get food poisoning far more often than Brits. Is American IT just as sickening?

Opinion When two stories from opposite ends of the IT universe boil down to the same thing, sound the klaxons. At the uber-fashionable AI end of tech, Meta has grudgingly complied with a ruling not to feed European social media crap into its training data. Meanwhile, in the industrial slums, 20 percent of running Microsoft SQL Server instances are now past the end of support.…

☐ β˜† βœ‡ The Register - Security

Admin took out a call center – and almost their career – with a cut and paste error

β€” June 24th 2024 at 07:29

Have you heard the one about the techie who forgot what was on the clipboard?

Who, me? Brace yourselves, gentle readers, for it is once again Monday, and the work week has commenced. Thankfully, The Reg is here with another dose of Who, Me? in which readers share tales of times they had a day worse than the one you're having. We hope it helps.…

☐ β˜† βœ‡ The Register - Security

Snowflake breach snowballs as more victims, perps, come forward

β€” June 24th 2024 at 02:14

Also: The leaked Apple internal tools that weren't; TV pirate pirates convicted; and some critical vulns, too

Infosec in brief The descending ball of trouble over at Snowflake keeps growing larger, with more victims – and even one of the alleged intruders – coming forward last week.…

☐ β˜† βœ‡ The Register - Security

Risk of installing dodgy extensions from Chrome store way worse than Google's letting on, study suggests

β€” June 23rd 2024 at 10:36

All depends on how you count it – Chocolate Factory claims 1% fail rate

Google this week offered reassurance that its vetting of Chrome extensions catches most malicious code, even as it acknowledged that "as with any software, extensions can also introduce risk."…

☐ β˜† βœ‡ The Register - Security

From network security to nyet work in perpetuity: What's up with the Kaspersky US ban?

β€” June 22nd 2024 at 08:16

It's been a long time coming. Now our journos speak their brains

Kettle The US government on Thursday banned Kaspersky Lab from selling its antivirus and other products in America from late July, and from issuing updates and malware signatures from October.…

☐ β˜† βœ‡ The Register - Security

Change Healthcare finally spills the tea on what medical data was stolen by cyber-crew

β€” June 21st 2024 at 21:33

'Substantial proportion' of America to get a little note from next month

Change Healthcare is formally notifying some of its pharmacy and hospital customers that their patients' data was stolen from it by ransomware criminals back in February – and for the first time has concretely disclosed the types of information swiped during that IT intrusion.…

☐ β˜† βœ‡ The Register - Security

Uncle Sam sanctions Kaspersky's top bosses – but not Mr K himself

β€” June 21st 2024 at 20:23

Here's America's list of the supposedly dirty dozen

Uncle Sam took another swing at Kaspersky Lab today and sanctioned a dozen C-suite and senior-level executives at the antivirus maker, but spared CEO and co-founder Eugene Kaspersky.…

☐ β˜† βœ‡ The Register - Security

Phoenix UEFI flaw puts long list of Intel chips in hot seat

β€” June 21st 2024 at 16:27

Researchers discuss it in same breath as BlackLotus and MosaicRegressor

A new vulnerability in UEFI firmware is threatening the security of a wide range of Intel chip families in a similar fashion to BlackLotus and others like it.…

☐ β˜† βœ‡ The Register - Security

Why attack surfaces are expanding

β€” June 21st 2024 at 14:58

Insights from Cloudflare

Webinar In the ever-evolving world of cybersecurity, understanding why attack surfaces are expanding is more critical than ever.…

☐ β˜† βœ‡ The Register - Security

Qilin cyber scum leak data they claim belongs to London hospitals’ pathology provider

β€” June 21st 2024 at 11:15

At least they didn’t get paid their $50M ransom demand

The ransomware gang responsible for the chaos at London hospitals kept true to its word and released a trove of data that it claims belongs to pathology services provider Synnovis.…

☐ β˜† βœ‡ The Register - Security

Since joining NATO, Sweden claims Russia has been borking Nordic satellites

β€” June 21st 2024 at 06:57

If Putin likes jammin', we hope NATO likes jammin' too

Sweden says its satellites have been impacted by "harmful interference" from Russia ever since the Nordic nation joined the North Atlantic Treaty Organization (NATO) last March.…

☐ β˜† βœ‡ The Register - Security

Coding error in forgotten API blamed for massive data breach

β€” June 21st 2024 at 05:38

Australian telco Optus allegedly left redundant website with poor access controls online for years

The data breach at Australian telco Optus, which saw over nine million customers' personal information exposed, has been blamed on a coding error that broke API access controls, and was left in place for years.…

☐ β˜† βœ‡ The Register - Security

Crooks get their hands on 500K+ radiology patients' records in cyber-attack

β€” June 20th 2024 at 21:43

Two ransomware gangs bragged of massive theft of personal info and medical files

Consulting Radiologists has notified almost 512,000 patients that digital intruders accessed their personal and medical information during a February cyberattack.…

☐ β˜† βœ‡ The Register - Security

Biden bans Kaspersky: No more sales, updates in US

β€” June 20th 2024 at 21:07

Blockade begins July 20 on national security grounds as antivirus slinger vows to fight back

The Biden administration today banned the sale of Kaspersky Lab products and services in the United States, declaring the Russian biz a national security risk.…

☐ β˜† βœ‡ The Register - Security

Car dealer software bigshot CDK pulls systems offline twice amid 'cyber incident'

β€” June 20th 2024 at 20:50

Downtime set to crash into next week

The vendor behind the software on which nearly 15,000 car dealerships across the US rely says an ongoing "cyber incident" has forced it to pull systems offline for a second time in as many days.…

☐ β˜† βœ‡ The Register - Security

Crypto exchange Kraken accuses blockchain security outfit CertiK of extortion

β€” June 20th 2024 at 17:35

Researchers allegedly stole $3M using the vulnerability, then asked how much it was really worth

Kraken, one of the largest cryptocurrency exchanges in the world, has accused a trio of security researchers of discovering a critical bug, expoliting it to steal millions in digital cash, then using stolen funds to extort the exchange for more.…

☐ β˜† βœ‡ The Register - Security

Russia's cyber spies still threatening French national security, democracy

β€” June 20th 2024 at 12:27

Publishing right before a major election is apparently just a coincidence

A fresh report into the Nobelium offensive cyber crew published by France's computer emergency response team (CERT-FR) highlights the group's latest tricks as the country prepares for a major election and to host this year's Olympic and Paralympic Games.…

☐ β˜† βœ‡ The Register - Security

Qilin: We knew our Synnovis attack would cause a healthcare crisis at London hospitals

β€” June 20th 2024 at 10:29

Cybercriminals claim they used a zero-day to breach pathology provider’s systems

Interview The ransomware gang responsible for a healthcare crisis at London hospitals says it has no regrets about its cyberattack, which was entirely deliberate, it told The Register in an interview.…

☐ β˜† βœ‡ The Register - Security

Amtrak confirms crooks are breaking into accounts using creds swiped from other DBs

β€” June 19th 2024 at 13:00

Railco goes full steam ahead with notification letters to Rewards users about spilled card details and more

US rail service Amtrak is writing to users of its Guest Rewards program to inform them that their data is potentially at risk following a derailment of their individual account security. …

☐ β˜† βœ‡ The Register - Security

That PowerShell 'fix' for your root cert 'problem' is a malware loader in disguise

β€” June 19th 2024 at 07:27

Control-C, Control-V, Enter ... Hell

Crafty criminals are targeting thousands of orgs around the world in social-engineering attacks that use phony error messages to trick users into running malicious PowerShell scripts. …

☐ β˜† βœ‡ The Register - Security

Rogue uni IT director pleads guilty after fraudulently buying $2.1M of tech

β€” June 18th 2024 at 23:46

Two decades in the clink would be quite an education

A now-former IT director has pleaded guilty to defrauding the university at which he was employed – and a computer equipment supplier – for $2.1 million over five years.…

☐ β˜† βœ‡ The Register - Security

Dark-web kingpin puts 'stolen' internal AMD databases, source code up for sale

β€” June 18th 2024 at 23:01

Chip designer really gonna need to channel some Zen right now

Updated AMD's IT team is no doubt going through its logs today after cyber-crooks put up for sale what is claimed to be internal data stolen from the US microprocessor designer.…

☐ β˜† βœ‡ The Register - Security

EU attempt to sneak through new encryption-eroding law slammed by Signal, politicians

β€” June 18th 2024 at 22:22

If you call 'client-side scanning' something like 'upload moderation,' it still undermines privacy, security

On Thursday, the EU Council is scheduled to vote on a legislative proposal that would attempt to protect children online by disallowing confidential communication.…

☐ β˜† βœ‡ The Register - Security

CHERI Alliance formed to promote memory security tech ... but where's Arm?

β€” June 18th 2024 at 15:04

Academic-industry project takes next step as key promoter chip designer licks its wounds

Updated A group of technology organizations has formed the CHERI Alliance CIC (Community Interest Company) to promote industry adoption of the security technology focused on memory access.…

☐ β˜† βœ‡ The Register - Security

Uncle Sam ends financial support to orgs hurt by Change Healthcare attack

β€” June 18th 2024 at 13:15

Billions of dollars made available but worst appears to be over

The US government is winding down its financial support for healthcare providers originally introduced following the ransomware attack at Change Healthcare in February.…

☐ β˜† βœ‡ The Register - Security

NHS boss says Scottish trust wouldn't give cyberattackers what they wanted

β€” June 18th 2024 at 11:29

CEO of Dumfries and Galloway admits circa 150K people should assume their details leaked

The chief exec at NHS Dumfries and Galloway will write to thousands of folks in the Scottish region whose data was stolen by criminals, admitting the lot of it was published after the trust did not give in to the miscreants' demands.…

☐ β˜† βœ‡ The Register - Security

VMware by Broadcom warns of two critical vCenter flaws, plus a nasty sudo bug

β€” June 18th 2024 at 06:08

Specially crafted network packet could allow remote code execution and access to VM fleets

VMware by Broadcom has revealed a pair of critical-rated flaws in vCenter Server – the tool used to manage virtual machines and hosts in its flagship Cloud Foundation and vSphere suites.…

☐ β˜† βœ‡ The Register - Security

Arm security defense shattered by speculative execution 95% of the time

β€” June 18th 2024 at 01:11

'TikTag' security folks find anti-exploit mechanism rather fragile

In 2018, chip designer Arm introduced a hardware security feature called Memory Tagging Extensions (MTE) as a defense against memory safety bugs. But it may not be as effective as first hoped.…

☐ β˜† βœ‡ The Register - Security

Shoddy infosec costs PwC spinoff and NMA $11.3M in settlement with Uncle Sam

β€” June 17th 2024 at 23:47

Pen-testing tools didn't work – and personal info of folks hit by pandemic started appearing in search engines

Updated Two consulting firms, Guidehouse and Nan McKay and Associates, have agreed to pay a total of $11.3 million to resolve allegations of cybersecurity failings over their roll-out of COVID-19 assistance.…

☐ β˜† βœ‡ The Register - Security

Suspected bosses of $430M dark-web Empire Market charged in US

β€” June 17th 2024 at 20:13

Cybercrime super-souk's Dopenugget and Zero Angel may face life behind bars if convicted

The two alleged administrators of Empire Market, a dark-web bazaar that peddled drugs, malware, digital fraud, and other illegal stuff, have been detained on charges related to owning and operating the illicit souk.…

☐ β˜† βœ‡ The Register - Security

Blackbaud has to cough up a few million dollars more over 2020 ransomware attack

β€” June 17th 2024 at 17:45

Four years on and it's still paying for what California attorney general calls 'unacceptable' practice

Months after escaping without a fine from the US Federal Trade Commission (FTC), the luck of cloud software biz Blackbaud ran out when it came to reaching a settlement with California's attorney general.…

☐ β˜† βœ‡ The Register - Security

Cops cuff 22-year-old Brit suspected of being Scattered Spider leader

β€” June 17th 2024 at 13:00

Spanish plod make arrest at airport before he jetted off to Italy

Spanish police arrested a person they allege to be the leader of the notorious cybercrime gang Scattered Spider as he boarded a private flight to Naples.…

☐ β˜† βœ‡ The Register - Security

AWS is pushing ahead with MFA for privileged accounts. What that means for you ...

β€” June 17th 2024 at 11:18

The clock is ticking – why not try a passkey?

Heads up: Amazon Web Services is pushing ahead with making multi-factor authentication (MFA) mandatory for certain users, and we love to see it.…

☐ β˜† βœ‡ The Register - Security

UK's Total Fitness exposed nearly 500K images of members, staff through unprotected database

β€” June 17th 2024 at 10:35

Health club chain headed for the spa on choose-a-password day

Exclusive A cybersecurity researcher claims UK health club and gym chain Total Fitness bungled its data protection responsibilities by failing to lock down a database chock-full of members' personal data.…

☐ β˜† βœ‡ The Register - Security

Notorious cyber gang UNC3944 attacks vSphere and Azure to run VMs inside victims' infrastructure

β€” June 17th 2024 at 06:34

Who needs ransomware when you can scare techies into coughing up their credentials?

Notorious cyber gang UNC3944 – the crew suspected of involvement in the recent attacks on Snowflake and MGM Entertainment, and plenty more besides – has changed its tactics and is now targeting SaaS applications…

☐ β˜† βœ‡ The Register - Security

That didn't take long: Replacement for SORBS spam blacklist arises ... sort of

β€” June 17th 2024 at 01:59

Also: Online adoption cyberstalker nabbed; Tesla trade secrets thief pleads guilty; and a critical ASUS Wi-Fi vuln

Infosec in brief A popular spam blocklist service that went offline earlier this month has advised users it is down permanently – but at least one potential candidate is stepping up to try to fill the threat intelligence void.…

☐ β˜† βœ‡ The Register - Security

Japan's space junk cleaner hunts down major target

β€” June 17th 2024 at 00:44

Plus: Australia to age limit social media; Hong Kong's robo-dogs; India's new tech minister

Asia in brief The space junk cleaning mission launched by Japan's Aerospace Exploration Agency (JAXA) has successfully hunted down one of its targets.…

☐ β˜† βœ‡ The Register - Security

Microsoft answered Congress' questions on security. Now the White House needs to act

β€” June 15th 2024 at 01:20

Business as usual needs a real change

Feature Microsoft president Brad Smith struck a conciliatory tone regarding his IT giant's repeated computer security failings during a congressional hearing on Thursday – while also claiming the Windows maker is above the rule of law, at least in China.…

☐ β˜† βœ‡ The Register - Security

Stanford Internet Observatory wilts under legal pressure during election year

β€” June 14th 2024 at 21:38

Because who needs disinformation research at times like these

The Stanford Internet Observatory (SIO), which for the past five years has been studying and reporting on social media disinformation, is being reimagined with new management and fewer staff following the recent departure of research director Renee DiResta.…

☐ β˜† βœ‡ The Register - Security

Meta won't train AI on Euro posts after all, as watchdogs put their paws down

β€” June 14th 2024 at 20:46

Facebook parent calls step forward for privacy a 'step backwards'

Meta has caved to European regulators, and agreed to pause its plans to train AI models on EU users' Facebook and Instagram users' posts β€” a move that the social media giant said will delay its plans to launch Meta AI in the economic zone.…

☐ β˜† βœ‡ The Register - Security

Nigerian faces up to 102 years in the slammer for $1.5M phishing scam

β€” June 14th 2024 at 20:15

Crook and his alleged co-conspirators said to have used Discord to coordinate

A Nigerian national has been convicted of participating in a business email compromise (BEC) scam worth $1.5 million after a jury found him guilty on all counts.…

☐ β˜† βœ‡ The Register - Security

Ukraine busts SIM farms targeting soldiers with spyware

β€” June 14th 2024 at 13:22

Russia recruits local residents to support battlefield goals

Infrastructure that enabled two pro-Russia Ukraine residents to break into soldiers' devices and deploy spyware has been dismantled by the Security Service of Ukraine (SSU).…

☐ β˜† βœ‡ The Register - Security

French state bidding for piece of Atos, offers €700M

β€” June 14th 2024 at 11:33

Big data + security division could be owed by the government and its people

The French government has confirmed an offer of €700 million ($748 million) for key assets of ailing IT services giant Atos, following the company’s acceptance of a restructuring deal earlier this week.…

☐ β˜† βœ‡ The Register - Security

Microsoft bigwig says the Feds catching Chinese spies in Exchange Online is the cloud working as intended

β€” June 14th 2024 at 00:40

'It's not our job to find the culprits – That's what we're paying you for' lawmaker scolds Brad Smith

Lawmakers on Thursday grilled Microsoft president Brad Smith about the Windows giant's businesses dealing in China β€” and the super-corp's repeated security failings β€” at a time when Beijing-backed spies are accused of breaking into Microsoft-hosted email accounts of American government officials.…

☐ β˜† βœ‡ The Register - Security

US Space Force wanted $77M to reinforce GPS – and Congress shot it down

β€” June 13th 2024 at 22:42

Can't we do this another way, like without these mini-sats costing $1B over 5 years, House reps wonder

A plan by America's Space Force to harden GPS against spoofing attacks may be going nowhere: A request by the service branch for $77 million of public cash to finish the work is struggling to get approval from Congress.…

☐ β˜† βœ‡ The Register - Security

Oracle Ads have had it: $2B operation shuts down after dwindling to $300M

β€” June 13th 2024 at 19:55

In this slightly more private era, your data ain't as profitable as it once was

Analysis Oracle Advertising is shutting down, CEO Safra Catz said during the database goliath's fiscal 2024 Q4 earnings call with Wall Street this week.…

❌