Summary

Total Articles Found: 29

Top sources:

Top Keywords:

Top Authors

Top Articles:

  • That's it. It's over. It's really over. From today, Adobe Flash Player no longer works. We're free. We can just leave
  • Amazon staffers took bribes, manipulated marketplace, leaked data including search algorithms – DoJ claims
  • Amazon Ring, Alexa accused of every nightmare IoT security fail you can imagine
  • Dropbox admits 130 of its private GitHub repos were copied after phishing attack
  • Zoom continues its catch-up security sprint with new training, bug bounty tweaks and promise of crypto playbook
  • CrowdStrike's Falcon Sensor also linked to Linux kernel panics and crashes
  • Uber reels from 'security incident' in which cloud systems seemingly hijacked
  • Zoom continues its catch-up security sprint with new training, bug bounty tweaks and promise of crypto playbook
  • Atlassian reveals critical flaws in almost everything it makes and touches
  • Near-undetectable malware linked to Russia's Cozy Bear

Police allege 'evil twin' of in-flight Wi-Fi used to steal passenger's credentials

Published: 2024-07-01 05:45:09

Popularity: 30

Author: Simon Sharwood

LLM Says: "Flying hack!"

Fasten your seat belts, secure your tray table, and try not to give away your passwords Australia's Federal Police (AFP) has charged a man with running a fake Wi-Fi network on at least one commercial flight and using it to harvest flier credentials for email and social media services.…

...more

Spam blocklist SORBS closed by its owner, Proofpoint

Published: 2024-06-07 06:27:13

Popularity: 42

Author: Simon Sharwood

LLM Says: ""Blocked and deleted""

Spammers will probably bid to buy it, so community is trying to find a better home for decades-old service Exclusive  The Spam and Open Relay Blocking System (SORBS) – a longstanding source of info on known sources of spam widely used to create blocklists – has been shuttered by its owner, cyber security software vendor Proofpoint.…

...more

Japanese government rejects Yahoo! infosec improvement plan

Published: 2024-04-17 05:44:08

Popularity: 12

Author: Simon Sharwood

Just doesn't believe it will sort out the mess that saw data leak from LINE messaging app Japan's government has considered the proposed security improvements developed by Yahoo!, found them wanting, and ordered the onetime web giant to take new measures.…

...more

CEO arranged his own cybersecurity, with predictable results

Published: 2023-12-29 08:01:05

Popularity: 15

Author: Simon Sharwood

Cleaning up after hackers is easy compared to surviving the politics of consultancy On Call  It’s the last Friday of 2023, but because the need for tech support never goes away neither does On Call, The Register’s Friday column in which readers share their tales of being asked to fix the unfeasible, in circumstances that are often indefensible.…

...more

Stop what you’re doing and patch this critical Confluence flaw, warns Atlassian

Published: 2023-10-31 05:05:59

Popularity: 11

Author: Simon Sharwood

Risk of ‘significant data loss’ for on-prem customers Atlassian has told customers they “must take immediate action” to address a newly discovered flaw in its Confluence collaboration tool.…

...more

Amazon Ring, Alexa accused of every nightmare IoT security fail you can imagine

Published: 2023-06-01 06:33:10

Popularity: 280

Author: Simon Sharwood

Staff able to watch customers in the bathroom? Tick! Obviously shabby infosec? Tick! Training AI as an excuse for data retention? Tick! America's Federal Trade Commission has made Amazon a case study for every cautionary tale about how sloppily designed internet-of-things devices and associated services represent a risk to privacy – and made the cost of those actions, as alleged, a mere $30.8 million.…

...more

Dropbox admits 130 of its private GitHub repos were copied after phishing attack

Published: 2022-11-01 23:52:06

Popularity: 207

Author: Simon Sharwood

Personal info and data safe, stolen code not critical, apparently Dropbox has said it was successfully phished, resulting in someone copying 130 of its private GitHub code repositories and swiping some of its secret API credentials.…

...more

DoJ ‘very disappointed’ with probation sentence for Capital One hacker Paige Thompson

Published: 2022-10-05 05:31:06

Popularity: 18

Author: Simon Sharwood

‘This is not what justice looks like’ says official on sanction for leak of 100 million records Convicted wire fraud perpetrator Paige Thompson (aka "erratic") has been sentenced to time served and five years of probation with location and computer monitoring, prompting U.S. Attorney Nick Brown to label the sanctions unsatisfactory.…

...more

Uber reels from 'security incident' in which cloud systems seemingly hijacked

Published: 2022-09-16 03:13:43

Popularity: 165

Author: Simon Sharwood

AWS and G Suite admin accounts likely popped, HackerOne bug bounty page hit, and more Updated  Uber is tonight reeling from what looks like a substantial cybersecurity breach.…

...more

Atlassian reveals critical flaws in almost everything it makes and touches

Published: 2022-07-21 01:54:25

Popularity: 89

Author: Simon Sharwood

Fixes issued, warns it 'has not exhaustively enumerated all potential consequences' Atlassian has warned users of its Bamboo, Bitbucket, Confluence, Fisheye, Crucible, and Jira products that a pair of critical-rated flaws threaten their security.…

...more

Near-undetectable malware linked to Russia's Cozy Bear

Published: 2022-07-06 05:27:10

Popularity: 78

Author: Simon Sharwood

The fun folk who attacked Solar Winds using a poisoned CV and tools from the murky world of commercial hackware Palo Alto Networks' Unit 42 threat intelligence team has claimed that a piece of malware that 56 antivirus products were unable to detect is evidence that state-backed attackers have found new ways to go about the evil business.…

...more

Israel plans ‘Cyber-Dome’ to defeat digital attacks from Iran and others

Published: 2022-06-30 02:15:11

Popularity: 19

Author: Simon Sharwood

Already has 'Iron Dome' – does it need another hero? The new head of Israel's National Cyber Directorate (INCD) has announced the nation intends to build a "Cyber-Dome" – a national defense system to fend off digital attacks.…

...more

Tencent admits to poisoned QR code attack on QQ chat platform

Published: 2022-06-28 04:31:13

Popularity: 12

Author: Simon Sharwood

Could it be Beijing was right about games being bad for China? Chinese web giant Tencent has admitted to a significant account hijack attack on its QQ.com messaging and social media platform.…

...more

Researchers find 134 flaws in the way Word, PDFs, handle scripts

Published: 2022-05-13 07:54:07

Popularity: 22

Author: Simon Sharwood

‘Cooperative mutation’ spots problems that checking code alone will miss Black Hat Asia  Security researchers have devised a tool that detects flaws in the way apps like Microsoft Word and Adobe Acrobat process JavaScript, and it's proven so effective they've found 134 bugs – 59 of them considered worthy of a fix by vendors, 33 assigned a CVE number, and 17 producing bug bounty payments totaling $22,000.…

...more

Okta acknowledges 'mistake' in handling of Lapsus$ attack

Published: 2022-03-28 04:14:07

Popularity: 30

Author: Simon Sharwood

Changes story again to say customers weren't in danger, admits it waited for incident report instead of asking tough questions Identity-management-as-a-service outfit Okta has acknowledged that it made an important mistake in its handling of the attack on a supplier by extortion gang Lapsus$.…

...more

WTF? Microsoft makes fixing deadly OMIGOD flaws on Azure your job

Published: 2021-09-17 04:58:10

Popularity: 53

Author: Simon Sharwood

Clouds usually fix this sort of thing before bugs go public. This time it's best to assume you need to do this yourself Microsoft Azure users running Linux VMs in the IT giant's Azure cloud need to take action to protect themselves against the four "OMIGOD" bugs in the Open Management Infrastructure (OMI) framework, because Microsoft hasn't raced to do it for them.…

...more

Kaseya restores SaaS, then 'performance issues' force a do-over

Published: 2021-07-13 05:57:10

Popularity: 15

Author: Simon Sharwood

What’s another 20 minutes of sudden unplanned downtime between friends? Kaseya has fully restored its SaaS product, then quickly inflicted a little more unplanned downtime on users.…

...more

That's it. It's over. It's really over. From today, Adobe Flash Player no longer works. We're free. We can just leave

Published: 2021-01-12 01:41:14

Popularity: 1726

Author: Simon Sharwood

Post-Flashpocalypse, we stumble outside, hoping no one ever creates software as insecure as that ever again Adobe has finally and formally killed Flash.…

...more

Amazon staffers took bribes, manipulated marketplace, leaked data including search algorithms – DoJ claims

Published: 2020-09-21 02:13:11

Popularity: 425

Author: Simon Sharwood

Banned merchants restored, rivals’ stores binned, cash sent around town in an Uber, it is alleged US prosecutors claim six people bribed corrupt Amazon insiders to rig the the web giant's Marketplace in their favor and leak terabytes of data including some search algorithms.…

...more

Twitter says spear-phishing attack hooked its staff and led to celebrity account hijack

Published: 2020-07-31 05:27:08

Popularity: 73

Author: Simon Sharwood

Attack came in waves that probed for staff with access to the creds crims craved Twitter has offered further explanation of the celebrity account hijack hack that saw 130 users’ timelines polluted with a Bitcoin scam.…

...more

Zoom continues its catch-up security sprint with new training, bug bounty tweaks and promise of crypto playbook

Published: 2020-05-21 06:02:09

Popularity: 200

Author: Simon Sharwood

Sigh. How many users did it have before it started this stuff? Zoom has outlined more about its efforts to improve its security.…

...more

Zoom continues its catch-up security sprint with new training, bug bounty tweaks and promise of crypto playbook

Published: 2020-05-21 06:02:09

Popularity: 99

Author: Simon Sharwood

Sigh. How many users did it have before it started this stuff? Zoom has outlined more about its efforts to improve its security.…

...more

Dropbox dropped the ball on security, haemorrhaging customer and third-party info

Published: 2024-05-02 00:58:10

Popularity: 18

Author: Simon Sharwood

Only from its digital doc-signing service, which is isolated from its cloudy storage Dropbox has revealed a major attack on its systems that saw customers' personal information accessed by unknown and unauthorized entities.…

...more

Flaws in Chinese keyboard apps leave 750 million users open to snooping, researchers claim

Published: 2024-04-26 05:33:17

Popularity: 27

Author: Simon Sharwood

Huawei is OK, but Xiaomi, OPPO, and Samsung are in strife. And Honor isn't living its name Many Chinese keyboard apps, some from major handset manufacturers, can leak keystrokes to determined snoopers, leaving perhaps three quarters of a billion people at risk according to research from the University of Toronto’s Citizen Lab.…

...more

Release the hounds! Securing datacenters may soon need sniffer dogs

Published: 2024-07-18 00:54:10

Popularity: 7

Author: Simon Sharwood

LLM Says: "Sniff out security"

Nothing else can detect attackers with implants designed to foil physical security Sniffer dogs may soon become a useful means of improving physical security in datacenters, as increasing numbers of people are adopting implants like NFC chips that have the potential to enable novel attacks on access control tools.…

...more

CrowdStrike's Falcon Sensor also linked to Linux kernel panics and crashes

Published: 2024-07-21 23:51:18

Popularity: 182

Author: Simon Sharwood

LLM Says: "System Crash"

Rapid restore tool being tested as Microsoft estimates 8.5M machines went down Updated  CrowdStrike's now-infamous Falcon Sensor software, which last week led to widespread outages of Windows-powered computers, has also been linked to crashes of Linux machines.…

...more

Post-CrowdStrike, Microsoft to discourage use of kernel drivers by security tools

Published: 2024-07-29 06:30:14

Popularity: 26

Author: Simon Sharwood

LLM Says: ""Driver's Seat""

Now there's an idea – parsing config data in user mode Updated  Microsoft has vowed to reduce cybersecurity vendors' reliance on kernel-mode code, which was at the heart of the CrowdStrike super-snafu this month.…

...more

Telegram apologizes to South Korea and takes down smutty deepfakes

Published: 2024-09-04 04:28:14

Popularity: 10

Author: Simon Sharwood

LLM Says: "NSFW fail"

Unclear if this is a sign controversial service is cleaning up its act everywhere Controversial social network Telegram has co-operated with South Korean authorities and taken down 25 videos depicting sex crimes.…

...more

To patch this server, we need to get someone drunk

Published: 2024-09-06 07:28:05

Popularity: 13

Author: Simon Sharwood

LLM Says: ""Drunk coding""

When maintenance windows are hard to open, a little lubrication helps On Call  The Register understands consuming alcohol is quite a popular way to wind down from the working week, but each Friday we get the party started early with a new and sober instalment of On Call, the reader contributed column in which you share stories about the emotional hangovers you've earned delivering tech support.…

...more

end