Summary

Total Articles Found: 274

Top sources:

Top Keywords:

Top Authors

Top Articles:

  • Zoom's end-to-end encryption isn't actually end-to-end at all. Good thing the PM isn't using it for Cabinet calls. Oh, for f...
  • If you own one of these 45 Netgear devices, replace it: Kit maker won't patch vulnerable gear despite live proof-of-concept code
  • You may be distracted by the pandemic but FYI: US Senate panel OK's backdoors-by-the-backdoor EARN IT Act
  • Alleged Vault 7 leaker trial finale: Want to know the CIA's password for its top-secret hacking tools? 123ABCdef
  • Laptops given to British schools came preloaded with remote-access worm
  • That's it. It's over. It's really over. From today, Adobe Flash Player no longer works. We're free. We can just leave
  • 2001: Linux is cancer, says Microsoft. 2019: Hey friends, ah, can we join the official linux-distros mailing list, plz?
  • Three middle-aged Dutch hackers slipped into Donald Trump's Twitter account days before 2016 US election
  • Let's Encrypt? Let's revoke 3 million HTTPS certificates on Wednesday, more like: Check code loop blunder strikes
  • WTF is Boeing on? Not just customer databases lying around on the web. 787 jetliner code, too, security bugs and all

Police allege 'evil twin' of in-flight Wi-Fi used to steal passenger's credentials

Published: 2024-07-01 05:45:09

Popularity: 30

Author: Simon Sharwood

LLM Says: "Flying hack!"

Fasten your seat belts, secure your tray table, and try not to give away your passwords Australia's Federal Police (AFP) has charged a man with running a fake Wi-Fi network on at least one commercial flight and using it to harvest flier credentials for email and social media services.…

...more

Traeger security bugs bad news for grillers with neighborly beef

Published: 2024-07-03 16:24:09

Popularity: 64

Author: Connor Jones

LLM Says: "Burned neighbors"

Never risk it when it comes to brisket – make sure those updates are applied Keen meatheads better hope they haven't angered any cybersecurity folk before allowing their Traeger grills to update because a new high-severity vulnerability could be used for all kinds of high jinks.…

...more

TeamViewer says Russia broke into its corp IT network

Published: 2024-06-28 19:00:44

Popularity: 81

Author: Chris Williams

LLM Says: ""Russian hackers caught""

Same APT29 crew that hit Microsoft and SolarWinds. How close were we to a mega backdoor situation? Updated  TeamViewer says it was Russian intelligence that broke into its systems this week.…

...more

'Almost every Apple device' vulnerable to CocoaPods supply chain attack

Published: 2024-07-02 07:32:06

Popularity: 31

Author: Brandon Vigliarolo

LLM Says: "Vulnerable iOS"

Dependency manager used in millions of apps leaves a bitter taste CocoaPods, an open-source dependency manager used in over three million applications coded in Swift and Objective-C, left thousands of packages exposed and ready for takeover for nearly a decade – thereby creating opportunities for supply chain attacks on iOS and macOS apps, according to security researchers.…

...more

EU attempt to sneak through new encryption-eroding law slammed by Signal, politicians

Published: 2024-06-18 22:22:06

Popularity: 12

Author: Thomas Claburn

LLM Says: "Signal fail 🚫🔒"

If you call 'client-side scanning' something like 'upload moderation,' it still undermines privacy, security On Thursday, the EU Council is scheduled to vote on a legislative proposal that would attempt to protect children online by disallowing confidential communication.…

...more

Suspected bosses of $430M dark-web Empire Market charged in US

Published: 2024-06-17 20:13:02

Popularity: 9

Author: Jessica Lyons

LLM Says: "Dark web bust"

Dopenugget and Zero Angel may face life behind bars if convicted The two alleged administrators of Empire Market, a dark-web bazaar that peddled drugs, malware, digital fraud, and other illegal stuff, have been detained on charges related to owning and operating the illicit souk.…

...more

Arm security defense shattered by speculative execution 95% of the time

Published: 2024-06-18 01:11:09

Popularity: 18

Author: Thomas Claburn

LLM Says: ""Speculative fail""

'TikTag' security folks find anti-exploit mechanism rather fragile In 2018, chip designer Arm introduced a hardware security feature called Memory Tagging Extensions (MTE) as a defense against memory safety bugs. But it may not be as effective as first hoped.…

...more

Stanford Internet Observatory wilts under legal pressure during election year

Published: 2024-06-14 21:38:05

Popularity: 32

Author: Thomas Claburn

LLM Says: "Censored"

Because who needs disinformation research at times like these The Stanford Internet Observatory (SIO), which for the past five years has been studying and reporting on social media disinformation, is being reimagined with new management and fewer staff following the recent departure of research director Renee DiResta.…

...more

Hudson Rock yanks report fingering Snowflake employee creds snafu for mega-leak

Published: 2024-06-04 02:25:07

Popularity: 9

Author: Jessica Lyons

LLM Says: "Snowflaking fail"

Cloud storage giant lawyers up against infosec house Analysis  Hudson Rock, citing legal pressure from Snowflake, has removed its online report that claimed miscreants broke into the cloud storage and analytics giant's underlying systems and stole data from potentially hundreds of customers including Ticketmaster and Santander Bank.…

...more

Spam blocklist SORBS closed by its owner, Proofpoint

Published: 2024-06-07 06:27:13

Popularity: 42

Author: Simon Sharwood

LLM Says: ""Blocked and deleted""

Spammers will probably bid to buy it, so community is trying to find a better home for decades-old service Exclusive  The Spam and Open Relay Blocking System (SORBS) – a longstanding source of info on known sources of spam widely used to create blocklists – has been shuttered by its owner, cyber security software vendor Proofpoint.…

...more

Japanese government rejects Yahoo! infosec improvement plan

Published: 2024-04-17 05:44:08

Popularity: 12

Author: Simon Sharwood

Just doesn't believe it will sort out the mess that saw data leak from LINE messaging app Japan's government has considered the proposed security improvements developed by Yahoo!, found them wanting, and ordered the onetime web giant to take new measures.…

...more

NVD slowdown leaves thousands of vulnerabilities without analysis data

Published: 2024-03-22 13:45:07

Popularity: 17

Author: Steven J. Vaughan-Nichols

Security world reacts as NIST does a lot less of oft criticized, 'almost always thankless' work Opinion  The United States National Institute of Standards and Technology (NIST) has almost completely stopped adding analysis to Common Vulnerabilities and Exposures (CVEs) listed in the National Vulnerability Database. That means big headaches for anyone using CVEs to maintain their security. …

...more

Exposed: Chinese smartphone farms that run thousands of barebones mobes to do crime

Published: 2024-03-21 06:32:13

Popularity: 16

Author: Laura Dobberstein

Operators pack twenty phones into a chassis – then rack 'em and stack 'em ready to do evil Chinese upstarts are selling smartphone motherboards – and kit to run and manage them at scale – to operators of outfits that use them to commit various scams and crimes, according to an undercover investigation by state television broadcaster China Central Television (CCTV) revealed late last week.…

...more

Forget TikTok – Chinese spies want to steal IP by backdooring digital locks

Published: 2024-03-14 23:35:06

Popularity: 30

Author: Jessica Lyons

Uncle Sam can use this snooping tool, too, but that's beside the point Updated  There's another Chinese-manufactured product – joining the likes of TikTok, cars and semiconductors – that poses a national security risk to Americans: Electronic locks, such as those used in safes.…

...more

Font security 'still a Helvetica of a problem' says Australian graphics outfit Canva

Published: 2024-03-08 03:57:10

Popularity: 21

Author: Laura Dobberstein

Who knew that unzipping a font archive could unleash a malicious file Online graphic design platform Canva went looking for security problems in fonts, and found three – in "strange places."…

...more

Microsoft confirms Russian spies stole source code, accessed internal systems

Published: 2024-03-08 16:56:46

Popularity: 115

Author: Jessica Lyons

Still 'no evidence' of any compromised customer-facing systems, we're told Microsoft has now confirmed that the Russian cyberspies who broke into its executives' email accounts stole source code and gained access to internal systems. The Redmond giant also characterized the intrusion as "ongoing."…

...more

Judge orders NSO to cough up Pegasus super-spyware source code

Published: 2024-03-01 21:34:29

Popularity: 31

Author: Thomas Claburn

/* Hope no one ever reads these functions lmao */ NSO Group, the Israel-based maker of super-charged snoopware Pegasus, has been ordered by a federal judge in California to share the source code for "all relevant spyware" with Meta's WhatsApp.…

...more

European Court of Human Rights declares backdoored encryption is illegal

Published: 2024-02-15 07:26:08

Popularity: 49

Author: Thomas Claburn

Surprising third-act twist as Russian case means more freedom for all The European Court of Human Rights (ECHR) has ruled that laws requiring crippled encryption and extensive data retention violate the European Convention on Human Rights – a decision that may derail European data surveillance legislation known as Chat Control.…

...more

Ivanti discloses fifth vulnerability, doesn't credit researchers who found it

Published: 2024-02-09 21:30:14

Popularity: 27

Author: Connor Jones

Software company's claim of there being no active exploits also being questioned In disclosing yet another vulnerability in its Connect Secure, Policy Secure, and ZTA gateways, Ivanti has confused the third-party researchers who discovered it.…

...more

Raspberry Pi Pico cracks BitLocker in under a minute

Published: 2024-02-07 15:30:09

Popularity: 145

Author: Richard Speed

Windows encryption feature defeated by $10 and a YouTube tutorial We're very familiar with the many projects in which Raspberry Pi hardware is used, from giving old computers a new lease of life through to running the animated displays so beloved by retailers. But cracking BitLocker? We doubt the company will be bragging too much about that particular application.…

...more

Wikileaks source and former CIA worker Joshua Schulte sentenced to 40 years jail

Published: 2024-02-02 03:58:11

Popularity: 11

Author: Laura Dobberstein

'Vault 7' leak detailed cyber-ops including forged digital certs Joshua Schulte, a former CIA employee and software engineer accused of sharing material with WikiLeaks, was sentenced to 40 years in prison by the US Southern District of New York on Thursday.…

...more

Critical vulnerability in Mastodon is pounced upon by fast-acting admins

Published: 2024-02-02 18:32:09

Popularity: 16

Author: Connor Jones

Danger of remote account takeovers leaves lead devs scared of releasing many details Mastodon has called admins to action following the disclosure of a critical vulnerability affecting the decentralized social network favored by erstwhile Twitter lovers.…

...more

SolarWinds slams SEC lawsuit against it as 'unprecedented' victim blaming

Published: 2024-01-29 20:52:28

Popularity: 11

Author: Jessica Lyons Hardcastle

18,000 customers, including the Pentagon and Microsoft, may have other thoughts SolarWinds – whose network monitoring software was backdoored by Russian spies so that the biz's customers could be spied upon – has accused America's financial watchdog of seeking to "revictimise the victim" after the agency sued it over the 2020 attack.…

...more

Jenkins jitters as 45,000 servers still vulnerable to RCE attacks after patch released

Published: 2024-01-30 17:45:15

Popularity: 9

Author: Connor Jones

Multiple publicly available exploits have since been published for the critical flaw The number of public-facing installs of Jenkins servers vulnerable to a recently disclosed critical vulnerability is in the tens of thousands.…

...more

SSH shaken, not stirred by Terrapin vulnerability

Published: 2023-12-20 08:34:11

Popularity: 12

Author: Connor Jones

No need to panic, but grab those updates or mitigations anyway just to be safe A vulnerability in the SSH protocol can be exploited by a well-placed adversary to weaken the security of people's connections, if conditions are right.…

...more

Mozilla decides Trusted Types is a worthy security feature

Published: 2023-12-21 11:03:11

Popularity: 11

Author: Thomas Claburn

DOM-XSS attacks have become scarce on Google websites since TT debuted Mozilla last week revised its position on a web security technology called Trusted Types, which it has decided to implement in its Firefox browser.…

...more

Four in five Apache Struts 2 downloads are for versions featuring critical flaw

Published: 2023-12-21 14:13:13

Popularity: 16

Author: Connor Jones

Seriously, people - please check the stuff you fetch more carefully Security vendor Sonatype believes developers are failing to address the critical remote code execution (RCE) vulnerability in the Apache Struts 2 framework, based on recent downloads of the code.…

...more

Lapsus$ teen sentenced to indefinite detention in hospital for Nvidia, GTA cyberattacks

Published: 2023-12-21 22:15:10

Popularity: 23

Author: Jessica Lyons Hardcastle

Arion Kurtaj will remain hospitalized until a mental health tribunal says he can leave Two British teens who were members of the Lapsus$ gang have been sentenced for their roles in a cyber-crime spree that included compromising Uber, Nvidia, and fintech firm Revolut, and also blackmailing Grand Theft Auto maker Rockstar Games.…

...more

CEO arranged his own cybersecurity, with predictable results

Published: 2023-12-29 08:01:05

Popularity: 15

Author: Simon Sharwood

Cleaning up after hackers is easy compared to surviving the politics of consultancy On Call  It’s the last Friday of 2023, but because the need for tech support never goes away neither does On Call, The Register’s Friday column in which readers share their tales of being asked to fix the unfeasible, in circumstances that are often indefensible.…

...more

BreachForums boss busted for bond blunders – including using a VPN

Published: 2024-01-05 14:35:12

Popularity: 10

Author: Connor Jones

Fitzpatrick faces potentially decades in prison later this month, so may as well get some foreign Netflix in beforehand The cybercriminal behind BreachForums was this week arrested for violating the terms of his pretrial release and will now be held in custody until his sentencing hearing.…

...more

Bug hunters on your marks: TETRA radio encryption algorithms to enter public domain

Published: 2023-11-14 08:00:09

Popularity: 18

Author: Jessica Lyons Hardcastle

Emergency comms standard had five nasty flaws but will be opened to academic research A set of encryption algorithms used to secure emergency radio communications will enter the public domain after an about-face by the European Telecommunications Standards Institute (ETSI).…

...more

Ex-GCHQ software dev jailed for stabbing NSA staffer

Published: 2023-11-03 19:02:51

Popularity: 18

Author: Connor Jones

Terrorist ideology suspected to be motivation A former software developer for Britain's cyberspy agency is facing years in the slammer after being sentenced for stabbing a National Security Agency (NSA) official multiple times.…

...more

Stop what you’re doing and patch this critical Confluence flaw, warns Atlassian

Published: 2023-10-31 05:05:59

Popularity: 11

Author: Simon Sharwood

Risk of ‘significant data loss’ for on-prem customers Atlassian has told customers they “must take immediate action” to address a newly discovered flaw in its Confluence collaboration tool.…

...more

Ace holed: Hardware store empire felled by cyberattack

Published: 2023-10-31 17:33:06

Popularity: 197

Author: Richard Speed

US outfit scrambles to repair operations, restore processing of online orders Ace Hardware appears to have been the latest organization to succumb to a cyberattack, judging by its website and a message from CEO John Venhuizen.…

...more

DoJ: Ex-soldier tried to pass secrets to China after seeking a 'subreddit about spy stuff'

Published: 2023-10-09 15:15:15

Popularity: 19

Author: Jude Karabus

FBI agent claims sergeant with top clearance offered access to DoD tech systems A former US Army Sergeant with Top Secret US military clearance created a Word document entitled "Important Information to Share with Chinese Government," according to an FBI agent's sworn declaration.…

...more

Fresh curl tomorrow will patch 'worst' security flaw in ages

Published: 2023-10-10 14:30:08

Popularity: 25

Author: Richard Speed

It’s bad, folks. Pair of CVEs incoming on October 11 Updated  Start your patch engines – a new version of curl is due tomorrow that addresses a pair of flaws, one of which lead developer Daniel Stenberg describes as "probably the worst curl security flaw in a long time."…

...more

Squid games: 35 security holes still unpatched in proxy after 2 years, now public

Published: 2023-10-13 00:21:34

Popularity: 37

Author: Jessica Lyons Hardcastle

We'd like to say don't panic … but maybe? 35 vulnerabilities in the Squid caching proxy remain unfixed more than two years after being found and disclosed to the open source project's maintainers, according to the person who reported them.…

...more

Ex-Navy IT manager gets 5 years in slammer for 2018 database heist

Published: 2023-10-19 14:01:08

Popularity: 14

Author: Connor Jones

Seafaring cybercrim's wife faces similar sentence next month A former IT manager for the US Navy is facing a five-and-a-half year prison sentence for selling thousands of people's personal records on the dark web.…

...more

1Password confirms attacker tried to pull list of admin users after Okta intrusion

Published: 2023-10-24 15:15:23

Popularity: 27

Author: Connor Jones

Says logins are safe, as high-profile customers complain they knew about the breach before Okta 1Password is confirming it was attacked by cyber criminals after Okta was breached for the second time in as many years, but says customers' login details are safe.…

...more

Equifax scores £11.1M slap on wrist over 2017 mega breach

Published: 2023-10-13 12:46:38

Popularity: 28

Author: Connor Jones

Not quite a pound for every one of the 13.8 million affected UK citizens, and it could have been more The UK's Financial Conduct Authority (FCA) has fined Equifax a smidge over £11 million ($13.6 million) for severe failings that put millions of consumers at risk of financial crime.…

...more

Microsoft Bing Chat pushes malware via bad ads

Published: 2023-09-29 20:54:11

Popularity: 21

Author: Thomas Claburn

From AI to just plain aaaiiiee! Microsoft introduced its Bing Chat AI search assistant in February and a month later began serving ads alongside it to help cover costs.…

...more

Signal adopts new alphabet jumble to protect chats from quantum computers

Published: 2023-09-20 20:28:11

Popularity: 16

Author: Thomas Claburn

X3DH readied for retirement as PQXDH is rolled out Signal has adopted a new key agreement protocol in an effort to keep encrypted Signal chat messages protected from any future quantum computers.…

...more

Ex-Ubiquiti dev jailed for 6 years after stealing internal corp data, extorting bosses

Published: 2023-05-12 20:28:05

Popularity: 16

Author: Jessica Lyons Hardcastle

Momentary lapse in VPN led to stretch in the cooler, $1.6m bill Nickolas Sharp has been sentenced to six years in prison and ordered to pay almost $1.6 million to his now-former employer Ubiquiti – after stealing gigabytes of corporate data from the biz and then trying to extort almost $2 million from his bosses while posing as an anonymous hacker.…

...more

Google settles location tracking lawsuit for only $39.9M

Published: 2023-05-22 14:45:07

Popularity: 36

Author: Brandon Vigliarolo

Also, more OEM Android malware, Google's bug reports (mostly) ditch CVEs, and this week's critical vulns in brief  Google has settled another location tracking lawsuit, yet again being fined a relative pittance.…

...more

Amazon Ring, Alexa accused of every nightmare IoT security fail you can imagine

Published: 2023-06-01 06:33:10

Popularity: 280

Author: Simon Sharwood

Staff able to watch customers in the bathroom? Tick! Obviously shabby infosec? Tick! Training AI as an excuse for data retention? Tick! America's Federal Trade Commission has made Amazon a case study for every cautionary tale about how sloppily designed internet-of-things devices and associated services represent a risk to privacy – and made the cost of those actions, as alleged, a mere $30.8 million.…

...more

That 3CX supply chain attack keeps getting worse: Other vendors hit

Published: 2023-04-24 03:27:05

Popularity: 23

Author: Brandon Vigliarolo

Also, Finland sentences CEO of breach company to prison (kind of), and this week's laundry list of critical vulns In Brief  We thought it was probably the case when the news came out, but now it's been confirmed: The X_Trader supply chain attack behind the 3CX compromise last month wasn't confined to the telco developer.…

...more

Warning on SolarWinds-like supply-chain attacks: 'They're just getting bigger'

Published: 2023-03-03 11:33:13

Popularity: 38

Author: Jessica Lyons Hardcastle

Industry hasn't 'improved much at all' Mandiant's Eric Scales tells us SCSW  Back in 2020, Eric Scales led the incident response team investigating a state-backed software supply-chain attack that compromised application build servers and led to infections at government agencies and tech giants including Microsoft and Intel.…

...more

Google: You get crypto, you get crypto, almost everyone gets email crypto!

Published: 2023-03-01 01:38:14

Popularity: 6

Author: Jessica Lyons Hardcastle

Personal Gmail users still out of luck Google continued its client-side encryption rollout, the feature generally available to some Gmail and Calendar users who can now send and receive encrypted messages and meeting invites.…

...more

Feeling VEXed by software supply chain security? You’re not alone

Published: 2023-02-28 01:01:13

Popularity: 12

Author: Jessica Lyons Hardcastle

Chainguard CEO explains how to secure code given crims know to poison it at the source SCSW  The vast majority of off-the-shelf software is composed of imported components, whether that's open source libraries or proprietary code. And that spells a security danger: if someone can subvert one of those components, they can infiltrate every installation of applications using those dependencies.…

...more

Chromebook SH1MMER exploit promises admin jailbreak

Published: 2023-01-30 22:45:14

Popularity: 29

Author: Thomas Claburn

Schools' laptops are out if this one gets around, tho beware bricking Users of enterprise-managed Chromebooks now, for better or worse, have a way to break the shackles of administrative control through an exploit called SHI1MMER.…

...more

School laptop auction devolves into extortion allegation

Published: 2023-02-06 07:32:11

Popularity: 29

Author: Brandon Vigliarolo

Also: Atlassian says Jira has a 9.4 severity bug and the TSA issues milquetoast no-fly list security advisory When a Texas school district sold some old laptops at auction last year, it probably didn't expect to end up in a public legal fight with a local computer repair shop – but a debate over what to do with district data found on the liquidated machines has led to precisely that.…

...more

Codebreakers decipher Mary, Queen of Scots' secret letters 436 years after her execution

Published: 2023-02-09 08:30:05

Popularity: 41

Author: Jessica Lyons Hardcastle

Digital sleuths chop through crypto challenge in 'surreal' search A team of codebreakers discovered – and then cracked – more than 50 secret letters written by Mary Stuart, Queen of Scots while she was imprisoned in England by her cousin, Queen Elizabeth I. …

...more

Intel patches up SGX best it can after another load of security holes found

Published: 2023-02-15 20:40:11

Popularity: 17

Author: Dan Robinson

Plus bugs squashed in Server Platform Services and more Intel's Software Guard Extensions (SGX) are under the spotlight again after the chipmaker disclosed several newly discovered vulnerabilities affecting the tech, and recommended users update their firmware.…

...more

Stolen info on 400m+ Twitter accounts seemingly up for sale

Published: 2022-12-27 20:01:53

Popularity: 66

Author: Iain Thomson

Plus: Cracked Piers Morgan spews offensive tweets, not the usual kind Updated  A miscreant this Christmas weekend said they are willing to sell public and private info on more than 400 million Twitter accounts.…

...more

'Fully undetectable' Windows backdoor gets detected

Published: 2022-10-18 20:14:08

Popularity: 28

Author: Thomas Claburn

SafeBreach supposedly spots somewhat stealthy subversive software SafeBreach Labs says it has detected a novel fully undetectable (FUD) PowerShell backdoor, which calls into question the accuracy of threat naming.…

...more

Dropbox admits 130 of its private GitHub repos were copied after phishing attack

Published: 2022-11-01 23:52:06

Popularity: 207

Author: Simon Sharwood

Personal info and data safe, stolen code not critical, apparently Dropbox has said it was successfully phished, resulting in someone copying 130 of its private GitHub code repositories and swiping some of its secret API credentials.…

...more

Former Apple worker pleads guilty to $17m mail and wire fraud charges

Published: 2022-11-02 13:00:51

Popularity: 7

Author: Paul Kunert

Nefarious schemes included harvesting motherboard components and selling them back to Apple A one-time Apple employee working as a buyer within the iGiant's supply chain department has pleaded guilty to mail and wire fraud charges spanning multiple years, ultimately costing the company $17 million.…

...more

DoJ ‘very disappointed’ with probation sentence for Capital One hacker Paige Thompson

Published: 2022-10-05 05:31:06

Popularity: 18

Author: Simon Sharwood

‘This is not what justice looks like’ says official on sanction for leak of 100 million records Convicted wire fraud perpetrator Paige Thompson (aka "erratic") has been sentenced to time served and five years of probation with location and computer monitoring, prompting U.S. Attorney Nick Brown to label the sanctions unsatisfactory.…

...more

WordPress-powered sites backdoored after FishPig suffers supply chain attack

Published: 2022-09-15 02:12:07

Popularity: 28

Author: Brandon Vigliarolo

And two other security snafus in this web publishing world It's only been a week or so, and obviously there are at least three critical holes in WordPress plugins and tools that are being exploited in the wild right now to compromise loads of websites.…

...more

Uber reels from 'security incident' in which cloud systems seemingly hijacked

Published: 2022-09-16 03:13:43

Popularity: 165

Author: Simon Sharwood

AWS and G Suite admin accounts likely popped, HackerOne bug bounty page hit, and more Updated  Uber is tonight reeling from what looks like a substantial cybersecurity breach.…

...more

School chat app Seesaw abused to send 'inappropriate image' to parents, teachers

Published: 2022-09-16 21:45:39

Popularity: 31

Author: Jessica Lyons Hardcastle

This is why we don't reuse passwords, kids Parents and teachers received a link to an "inappropriate image" this week via Seesaw after miscreants hijacked accounts in a credential stuffing attack against the popular school messaging app.…

...more

Malwarebytes blocks Google, YouTube as malware

Published: 2022-09-21 15:56:01

Popularity: 96

Author: Jessica Lyons Hardcastle

Sounds like fair comment Updated  Google and its Youtube domains are being flagged as malicious by Malwarebytes as of Wednesday morning, blocking users from accessing a whole range of websites.…

...more

GPT-3 'prompt injection' attack causes bad bot manners

Published: 2022-09-19 13:37:53

Popularity: 13

Author: Brandon Vigliarolo

Also, EA goes kernel-deep to stop cheaters, PuTTY gets hijacked by North Korea, and more. In Brief  OpenAI's popular natural language model GPT-3 has a problem: It can be tricked into behaving badly by doing little more than telling it to ignore its previous orders.…

...more

Shape-shifting cryptominer savages Linux endpoints and IoT

Published: 2022-09-10 11:00:07

Popularity: 38

Author: Brandon Vigliarolo

Also, Authorities seize WT1SHOP selling 5.8m sets of PII, The North Face users face tough security hike In brief  AT&T cybersecurity researchers have discovered a sneaky piece of malware targeting Linux endpoints and IoT devices in the hopes of gaining persistent access and turning victims into crypto-mining drones.…

...more

PyPI warns of first-ever phishing campaign against its users

Published: 2022-08-26 19:21:03

Popularity: 21

Author: Thomas Claburn

On the bright side, top devs are getting hardware security keys The Python Package Index, better known among developers as PyPI, has issued a warning about a phishing attack targeting developers who use the service.…

...more

Critical hole in Atlassian Bitbucket allows any miscreant to hijack servers

Published: 2022-08-29 18:08:14

Popularity: 13

Author: Jessica Lyons Hardcastle

Grab and deploy this backend update if you offer even repo read access A critical command-injection vulnerability in multiple API endpoints of Atlassian Bitbucket Server and Data Center could allow an unauthorized attacker to remotely execute malware, and view, change, and even delete data stored in repositories.…

...more

Post-quantum crypto cracked in an hour with one core of an ancient Xeon

Published: 2022-08-03 06:59:06

Popularity: 207

Author: Laura Dobberstein

NIST's nifty new algorithm looks like it's in trouble One of the four encryption algorithms America's National Institute of Standards and Technology (NIST) considered as likely to resist decryption by quantum computers has had holes kicked in it by researchers using a single core of a regular Intel Xeon CPU, released in 2013.…

...more

Charter told to pay $7.3b in damages after cable installer murders grandmother

Published: 2022-07-27 00:54:07

Popularity: 284

Author: Chris Williams

Broadband giant says it will appeal jury verdict in negligence case Charter Communications must pay out $7 billion in damages after one of its Spectrum cable technicians robbed and killed an elderly woman, a jury decided Tuesday.…

...more

Apple network traffic takes mysterious detour through Russia

Published: 2022-07-27 18:56:38

Popularity: 186

Author: Thomas Claburn

Land of Putin capable of attacking routes in cyberspace as well as real world Apple's internet traffic took an unwelcome detour through Russian networking equipment for about twelve hours between July 26 and July 27.…

...more

Atlassian reveals critical flaws in almost everything it makes and touches

Published: 2022-07-21 01:54:25

Popularity: 89

Author: Simon Sharwood

Fixes issued, warns it 'has not exhaustively enumerated all potential consequences' Atlassian has warned users of its Bamboo, Bitbucket, Confluence, Fisheye, Crucible, and Jira products that a pair of critical-rated flaws threaten their security.…

...more

Thousands of websites run buggy WordPress plugin that allows complete takeover

Published: 2022-07-15 19:15:10

Popularity: 81

Author: Jessica Lyons Hardcastle

All versions are susceptible, there's no patch, so now's a good time to remove this add-on Miscreants have reportedly scanned almost 1.6 million websites in attempts to exploit an arbitrary file upload vulnerability in a previously disclosed buggy WordPress plugin.…

...more

Amazon gave Ring video to cops without consent or warrant 11 times so far in 2022

Published: 2022-07-14 13:45:12

Popularity: 23

Author: Laura Dobberstein

Got no time for that red tape in an emergency, says exec Updated  Amazon's home security wing Ring turned over footage to US law enforcement without permission from the devices' owners and seemingly without a warrant 11 times so far in 2022.…

...more

SCOTUS judges 'doxxed' after overturning Roe v Wade

Published: 2022-07-13 18:28:12

Popularity: 51

Author: Jessica Lyons Hardcastle

Physical and IP addresses as well as credit card info revealed in privacy breach The US Supreme Court justices who overturned Roe v. Wade last month may have been doxxed – had their personal information including physical and IP addresses, and credit card info revealed – according to threat intel firm Cybersixgill.…

...more

Marriott Hotels admits to third data breach in 4 years

Published: 2022-07-06 14:00:13

Popularity: 55

Author: Brandon Vigliarolo

Digital thieves made off with 20GB of internal documents and customer data Updated  Crooks have reportedly made off with 20GB of data from Marriott Hotels, which apparently included credit card info and internal company documents. …

...more

Actual quantum computers don't exist yet. The cryptography to defeat them may already be here

Published: 2022-07-05 22:36:33

Popularity: 29

Author: Thomas Claburn

NIST pushes ahead with CRYSTALS-KYBER, CRYSTALS-Dilithium, FALCON, SPHINCS+ algorithms The US National Institute of Standards and Technology (NIST) has recommended four cryptographic algorithms for standardization to ensure data can be protected as quantum computers become more capable of decryption.…

...more

Near-undetectable malware linked to Russia's Cozy Bear

Published: 2022-07-06 05:27:10

Popularity: 78

Author: Simon Sharwood

The fun folk who attacked Solar Winds using a poisoned CV and tools from the murky world of commercial hackware Palo Alto Networks' Unit 42 threat intelligence team has claimed that a piece of malware that 56 antivirus products were unable to detect is evidence that state-backed attackers have found new ways to go about the evil business.…

...more

Israel plans ‘Cyber-Dome’ to defeat digital attacks from Iran and others

Published: 2022-06-30 02:15:11

Popularity: 19

Author: Simon Sharwood

Already has 'Iron Dome' – does it need another hero? The new head of Israel's National Cyber Directorate (INCD) has announced the nation intends to build a "Cyber-Dome" – a national defense system to fend off digital attacks.…

...more

Tencent admits to poisoned QR code attack on QQ chat platform

Published: 2022-06-28 04:31:13

Popularity: 12

Author: Simon Sharwood

Could it be Beijing was right about games being bad for China? Chinese web giant Tencent has admitted to a significant account hijack attack on its QQ.com messaging and social media platform.…

...more

OpenSSL 3.0.5 awaits release to fix potential worse-than-Heartbleed flaw

Published: 2022-06-27 23:30:34

Popularity: 30

Author: Thomas Claburn

Though severity up for debate, and limited chips affected, broken tests hold back previous patch from distribution Updated  The latest version of OpenSSL v3, a widely used open-source library for secure networking using the Transport Layer Security (TLS) protocol, contains a memory corruption vulnerability that imperils x64 systems with Intel's Advanced Vector Extensions 512 (AVX512).…

...more

Mega's unbreakable encryption proves to be anything but

Published: 2022-06-22 20:58:14

Popularity: 26

Author: Thomas Claburn

Boffins devise five attacks to expose private files Mega, the New Zealand-based file-sharing biz co-founded a decade ago by Kim Dotcom, promotes its "privacy by design" and user-controlled encryption keys to claim that data stored on Mega's servers can only be accessed by customers, even if its main system is taken over by law enforcement or others.…

...more

RSAC branded a 'super spreader event' as attendees share COVID-19 test results

Published: 2022-06-16 21:56:13

Popularity: 143

Author: Jessica Lyons Hardcastle

That, and Black Hat, are about to reveal risk assessment skills of our cyber-risk experts RSA Conference  Quick show of hands: who came home from this year's RSA Conference without COVID-19?…

...more

GitHub saved plaintext passwords of npm users in log files, post mortem reveals

Published: 2022-05-27 12:15:14

Popularity: 80

Author: Richard Speed

Unrelated to the OAuth token attack, but still troubling as org reveals details of around 100,000 users were grabbed by the baddies GitHub has revealed it stored a "number of plaintext user credentials for the npm registry" in internal logs following the integration of the JavaScript package registry into GitHub's logging systems.…

...more

Apple M1 chip contains hardware vulnerability that bypasses memory defense

Published: 2022-06-10 11:00:08

Popularity: 60

Author: Thomas Claburn

MIT CSAIL boffins devise PACMAN attack to let existing exploits avoid pointer authentication Apple's M1 chip has been found to contain a hardware vulnerability that can be abused to disable one of its defense mechanisms against memory corruption exploits, giving such attacks a greater chance of success.…

...more

If you've got Intel inside, you probably need to get these security patches inside, too

Published: 2022-05-12 21:06:29

Popularity: 21

Author: Jessica Lyons Hardcastle

So. Many. BIOS. Bugs Intel has disclosed high-severity bugs in its firmware that's used in datacenter servers, workstations, mobile devices, storage products, and other gear. These flaws can be exploited to escalate privileges, leak information, or stop things from working.…

...more

Researchers find 134 flaws in the way Word, PDFs, handle scripts

Published: 2022-05-13 07:54:07

Popularity: 22

Author: Simon Sharwood

‘Cooperative mutation’ spots problems that checking code alone will miss Black Hat Asia  Security researchers have devised a tool that detects flaws in the way apps like Microsoft Word and Adobe Acrobat process JavaScript, and it's proven so effective they've found 134 bugs – 59 of them considered worthy of a fix by vendors, 33 assigned a CVE number, and 17 producing bug bounty payments totaling $22,000.…

...more

Communication around Heroku security incident dubbed 'train wreck'

Published: 2022-05-04 15:30:42

Popularity: 13

Author: Lindsay Clark

Users claim lack of transparency following compromise of Github tokens Efforts by Salesforce-owned cloud platform Heroku to manage a recent security incident are turning into a bit of a disaster, according to some users.…

...more

F5, Cisco admins: Stop what you're doing and check if you need to install these patches

Published: 2022-05-06 02:06:39

Popularity: 26

Author: Jeff Burt

BIG-IP iControl authentication bypass, NFV VM escape, and more Updated  F5 Networks and Cisco this week issued warnings about serious, and in some cases critical, security vulnerabilities in their products.…

...more

Okta acknowledges 'mistake' in handling of Lapsus$ attack

Published: 2022-03-28 04:14:07

Popularity: 30

Author: Simon Sharwood

Changes story again to say customers weren't in danger, admits it waited for incident report instead of asking tough questions Identity-management-as-a-service outfit Okta has acknowledged that it made an important mistake in its handling of the attack on a supplier by extortion gang Lapsus$.…

...more

Hackers remotely start, unlock Honda Civics with $300 tech

Published: 2022-03-25 15:00:05

Popularity: 168

Author: Brandon Vigliarolo

Any models made between 2016 and 2020 can have key fob codes sniffed and re-transmitted If you're driving a Honda Civic manufactured between 2016 and 2020, this newly reported key fob hijack should start your worry engine.…

...more

Millions of APC Smart-UPS devices vulnerable to TLStorm

Published: 2022-03-09 12:29:32

Popularity: 177

Author: Laura Dobberstein

Critical vulns spotted in popular Schneider kit If you're managing a smart model from ubiquitous uninterrupted power supply (UPS) device brand APC, you need to apply updates now – a set of three critical vulnerabilities are making Smart-UPS devices a possible entry point for network infiltration.…

...more

Another data-leaking Spectre bug found, smashes Intel, Arm defenses

Published: 2022-03-15 09:22:14

Popularity: 21

Author: Thomas Claburn

Your processor design fell off the vulnerability tree and hit every branch on the way down Analysis  Intel this month published an advisory to address a novel Spectre v2 vulnerability in its processors that can be exploited by malware to steal data from memory that should otherwise be off limits.…

...more

OpenSSL patches crash-me bug triggered by rogue certs

Published: 2022-03-15 20:40:18

Popularity: 18

Author: Brandon Vigliarolo

Bad data can throw vulnerable apps and services for an infinite loop A bug in OpenSSL certificate parsing leaves systems open to denial-of-service attacks from anyone wielding an explicit curve. …

...more

The Windows malware on Ukraine CERT's radar

Published: 2022-03-16 03:28:10

Popularity: 17

Author: Jeff Burt

Government agencies impersonated, fake antivirus, another wiper, backdoors As Ukraine fights for survival against invading Russian forces, here's a taste of some of the malware the nation's Computer Emergency Response Team (CERT) is battling.…

...more

Adobe warns of second critical security hole in Adobe Commerce, Magento

Published: 2022-02-18 19:20:08

Popularity: 15

Author: Gareth Corfield

As sanctioned Russian infosec firm says it has working exploit code Adobe has put out a warning about another critical security bug affecting its Magento/Adobe Commerce product – and IT pros need to install a second patch after an initial update earlier this week failed to fully plug the first one.…

...more

Linux Snap package tool fixes make-me-root bugs

Published: 2022-02-19 00:15:57

Popularity: 15

Author: Gareth Corfield

Or you could think of them as a superuser password reset function The snap-confine tool in the Linux world's Snap software packaging system can be potentially exploited by ordinary users to gain root powers, says Qualys.…

...more

Worried about occasional npm malware scares? It's more common than you may think

Published: 2022-02-03 01:05:07

Popularity: 31

Author: Thomas Claburn

WhiteSource says it spotted 1,300 malicious JavaScript packages in 2021 alone Malware gets spotted in GitHub's npm registry every few months, elevating concerns about the software supply chain until attention gets diverted and worries recede until the next fire drill.…

...more

Remote code execution vulnerability in Samba due to macOS interop module

Published: 2022-02-02 17:57:05

Popularity: 17

Author: Liam Proven

Patch now An exploit in Samba 4 allowed remote code as root due to a bug in its support for Mac clients. It's fixed in 4.13.17, 4.14.12 and 4.15.5, and in case you can't update, there are patches.…

...more

Infosec chap: I found a way to hijack your web accounts, turn on your webcam from Safari – and Apple gave me $100k

Published: 2022-01-26 08:32:13

Popularity: 30

Author: Gareth Corfield

Now you see a harmless PNG. Now it's a malicious payload. Look into my eyes A security bod scored a $100,500 bug bounty from Apple after discovering a vulnerability in Safari on macOS that could have been exploited by a malicious website to potentially access victims' logged-in online accounts – and even their webcams.…

...more

When the world ends, all that will be left are cockroaches and new Rowhammer attacks: RAM defenses broken again

Published: 2021-11-15 21:46:49

Popularity: 19

Author: Thomas Claburn

Blacksmith is latest hammer horror Boffins at ETH Zurich, Vrije Universiteit Amsterdam, and Qualcomm Technologies have found that varying the order, regularity, and intensity of rowhammer attacks on memory chips can defeat defenses, thereby compromising security on any device with DRAM.…

...more

Shrootless: Microsoft found a way to evade Apple's SIP macOS filesystem protection

Published: 2021-10-29 18:01:30

Popularity: 12

Author: Gareth Corfield

LLM Says: "Sneaky microsoft"

Flaw could have let miscreants slide rootkits onto your iDesktop A vulnerability in MacOS that could let a malicious person install rootkits on Apple Macs has been patched, following its discovery and disclosure by Microsoft.…

...more

Microsoft Exchange Autodiscover protocol found leaking hundreds of thousands of credentials

Published: 2021-09-22 13:00:04

Popularity: 40

Author: Thomas Claburn

Email clients fail over to unexpected domains if they can't find the right resources A flaw in Microsoft's Autodiscover protocol, used to configure Exchange clients like Outlook, can cause user credentials to leak to miscreants in certain circumstances.…

...more

Researchers finger new APT group, FamousSparrow, for hotel attacks

Published: 2021-09-23 10:00:35

Popularity: 11

Author: Gareth Halfacree

Espionage motive mooted in attacks which hit industry, government too Researchers at security specialist ESET claim to have found a shiny new advanced persistent threat (APT) group dubbed FamousSparrow - after discovering its custom backdoor, SparrowDoor, on hotels and government systems around the world.…

...more

Microsoft warns: Active Directory FoggyWeb malware being actively used by Nobelium gang

Published: 2021-09-28 10:44:22

Popularity: 579

Author: Gareth Halfacree

Chief security adviser Roger Halbheer says best protection is to 'get off AD FS' Microsoft has warned of a new tool designed to exfiltrate credentials and introduce a backdoor into Active Directory servers that is under active use by the Nobelium threat actor group.…

...more

WTF? Microsoft makes fixing deadly OMIGOD flaws on Azure your job

Published: 2021-09-17 04:58:10

Popularity: 53

Author: Simon Sharwood

Clouds usually fix this sort of thing before bugs go public. This time it's best to assume you need to do this yourself Microsoft Azure users running Linux VMs in the IT giant's Azure cloud need to take action to protect themselves against the four "OMIGOD" bugs in the Open Management Infrastructure (OMI) framework, because Microsoft hasn't raced to do it for them.…

...more

Yes, of course there's now malware for Windows Subsystem for Linux

Published: 2021-09-17 22:06:04

Popularity: 116

Author: Thomas Claburn

Once dismissed proof-of-concept attack on Microsoft OS through WSL detected in the wild Updated  Linux binaries have been found trying to take over Windows systems in what appears to be the first publicly identified malware to utilize Microsoft's Windows Subsystem for Linux (WSL) to install unwelcome payloads.…

...more

Researchers find high-severity command injection vuln in Fortinet's web app firewall

Published: 2021-08-18 16:38:08

Popularity: 12

Author: Gareth Corfield

Mitigation: Don't let randomers from the internet log in to your firewall Updated  A command injection vulnerability exists in Fortinet's management interface for its FortiWeb web app firewall, according to infosec firm Rapid7.…

...more

Google: Linux kernel and its toolchains are underinvested by at least 100 engineers

Published: 2021-08-04 12:29:09

Popularity: 12

Author: Tim Anderson

Security not good enough, claims Chocolate Factory engineer Google's open security team has claimed the Linux kernel code is not good enough, with nearly 100 new fixes every week, and that at least 100 more engineers are needed to work on it.…

...more

Got a cheap Cisco router in your home office? If it's one of these, there's an exposed RCE hole you need to plug

Published: 2021-08-05 13:28:04

Popularity: 21

Author: Gareth Corfield

Patches issued for two CVE-rated vulns Cisco has published patches for critical vulns affecting the web management interface for some of its Small Business Dual WAN Gigabit routers – including a 9.8-rated nasty.…

...more

You'll want to shut down the Windows Print Spooler service (yes, again): Another privilege escalation bug found

Published: 2021-07-16 17:28:10

Popularity: 80

Author: Richard Speed

PrintNightmare? More like Groundhog Day for admins Microsoft has shared guidance revealing yet another vulnerability connected to its Windows Print Spooler service, saying it is "developing a security update."…

...more

Kaseya restores SaaS, then 'performance issues' force a do-over

Published: 2021-07-13 05:57:10

Popularity: 15

Author: Simon Sharwood

What’s another 20 minutes of sudden unplanned downtime between friends? Kaseya has fully restored its SaaS product, then quickly inflicted a little more unplanned downtime on users.…

...more

8-month suspended sentence for script kiddie who DDoS'd Labour candidate in runup to 2019 UK general election

Published: 2021-06-30 14:02:03

Popularity: 6

Author: Gareth Corfield

Now banned from using Tor or VPNs – and 'vanity' handles on social media A British script kiddie who DDoS'd a Labour Party parliamentary candidate's website in the runup to the last general election has been banned from using the Tor browser.…

...more

You can hijack Google Cloud VMs using DHCP floods, says this guy, once the stars are aligned and...

Published: 2021-06-30 00:02:21

Popularity: 14

Author: Thomas Claburn

An Ocean's 11 of exploitation involving guessable random numbers and hostname shenanigans Google Compute Engine virtual machines can be hijacked and made to hand over root shell access via a cunning DHCP attack, according to security researcher Imre Rad.…

...more

Report picks holes in the Linux kernel release signing process

Published: 2021-06-24 16:28:05

Popularity: 14

Author: Gareth Halfacree

Security procedures need documenting, improving, and mandating - though they're better than they used to be A report looking into the security of the Linux kernel's release signing process has highlighted a range of areas for improvement, from failing to mandate the use of hardware security keys for authentication to use of static keys for SSH access.…

...more

Dell SupportAssist contained RCE flaw allowing miscreants to remotely reflash your BIOS with code of their creation

Published: 2021-06-25 17:45:10

Popularity: 73

Author: Gareth Corfield

And it affects 129 models of PC and laptop... or about 30 million computers A chain of four vulnerabilities in Dell's SupportAssist remote firmware update utility could let malicious people run arbitrary code in no fewer than 129 different PCs and laptops models – while impersonating Dell to remotely upload a tampered BIOS.…

...more

Ex-NSA leaker Reality Winner released from prison early for 'exemplary' behavior

Published: 2021-06-14 20:36:21

Popularity: 31

Author: Katyanna Quach

Will be transferred to a halfway house, attorney continues to fight for presidential pardon Reality Winner, the former NSA intelligence contractor who leaked evidence of Russian interference in a US Presidential election to the press, has been released from prison.…

...more

DoS vulns in 3 open-source MQTT message brokers could leave users literally locked out of their homes or offices

Published: 2021-06-08 13:05:11

Popularity: 149

Author: Gareth Halfacree

If your IoT kit employs RabbitMQ, EMQ X or VerneMQ, it's time to get patching Synopsys Cybersecurity Research Centre (CyRC) has warned of easily triggered denial-of-service (DoS) vulnerabilities in three popular open-source Internet of Things message brokers: RabbitMQ, EMQ X, and VerneMQ.…

...more

We'd love to report on the outcome of the CREST exam cheatsheet probe, but UK infosec body won't publish it

Published: 2021-05-17 10:47:12

Popularity: 21

Author: Gareth Corfield

Why? It might reveal whistleblowers' names... British infosec accreditation body CREST has declared that it will not be publishing its full report into last year's exam-cheating scandal after all, triggering anger from the cybersecurity community.…

...more

Uptime funk: Microsoft has lifted availability of Azure Key Vault to 99.99%

Published: 2021-05-19 10:01:11

Popularity: 25

Author: Richard Speed

But beware the SLA: Just how much would an outage actually cost you? Microsoft has added another 9 to its availability guarantee for Azure Key Vault, taking the service to 99.99 per cent availability.…

...more

Icarus moment: Mozilla Thunderbird was saving OpenPGP keys in plaintext after encryption snafu

Published: 2021-05-24 17:15:05

Popularity: 40

Author: Gareth Corfield

Cockup has since been patched in latest release Mozilla Thunderbird spent the last couple of months saving some users’ OpenPGP keys in plain text – but that’s now been patched, the author of both the bug and the patch fixing it has told The Register.…

...more

Hard cheese: Stilton snap shared via EncroChat leads to drug dealer's downfall

Published: 2021-05-25 06:30:07

Popularity: 37

Author: Thomas Claburn

Brit thrown in the clink for 13 years after 'palm-print' lifted from internet photo A drug dealer's ham-handed OPSEC allowed British police to identify him from a picture of him holding a block of cheese, which led to his arrest, guilty plea, and a sentence of 13 years and six months in prison.…

...more

Digital Ocean springs a leak: Miscreant exploits hole to peep on unlucky customers' billing details for two weeks

Published: 2021-04-29 05:05:07

Popularity: 72

Author: Chris Williams

First that IPO and now this Digital Ocean on Wednesday said someone was able to snoop on some of its cloud subscribers' billing information via a now-patched vulnerability.…

...more

Nurserycam horror show: 'Secure' daycare video monitoring product beamed DVR admin creds to all users

Published: 2021-02-18 12:01:09

Popularity: 103

Author: Gareth Corfield

Company has a habit of reacting badly to vuln disclosures Updated  A parental webcam targeted at nursery schools was so poorly designed that anyone who downloaded its mobile app gained access to admin credentials, bypassing intended authentication, according to security pros – with one dad saying its creators brushed off his complaints about insecurities six years ago.…

...more

LastPass to limit fans of free password manager to one device type only – computer or mobile – from next month

Published: 2021-02-16 23:27:45

Popularity: 159

Author: Kieren McCarthy

Cough up if you want to use it with your laptop and phone Password manager LastPass has changed its terms and conditions to limit the free version of its code work on a single device type only per user, seemingly in an effort to force free folks into paying for its service.…

...more

Supermicro spy chips, the sequel: It really, really happened, and with bad BIOS and more, insists Bloomberg

Published: 2021-02-12 23:28:36

Popularity: 823

Author: Thomas Claburn

Server maker says latest article is 'a mishmash of disparate allegations' Following up on a disputed 2018 claim in its BusinessWeek publication that tiny spy chips were found on Supermicro server motherboards in 2015, Bloomberg on Friday doubled down by asserting that Supermicro's products were targeted by Chinese operatives for over a decade, that US intelligence officials have been aware of this, and that authorities kept this information quiet while crafting defenses in order to study the attack.…

...more

Chrome zero-day bug that is actively being abused by bad folks affects Edge, Vivaldi, and other Chromium-tinged browsers

Published: 2021-02-05 15:07:04

Popularity: 107

Author: Gareth Corfield

Install your updates pronto If you use Google Chrome or a Chromium-based browser such as Microsoft Edge, update it immediately and/or check it for updates over the coming days: there is a zero-day bug being "actively exploited" in the older version of Chrome that will also affect other vendors' browsers.…

...more

More patches for SolarWinds Orion after researchers find flaw allowing low-priv users to execute code, among others

Published: 2021-02-03 21:25:30

Popularity: 42

Author: Gareth Corfield

Probably not used by last year's US government-busting attackers, though As if that supply chain attack wasn't bad enough, SolarWinds has had to patch its Orion software again after eagle-eyed researchers discovered fresh vulnerabilities – including one that can be exploited to achieve remote code execution.…

...more

Google QUIC-ly left privacy behind in its quest for a speedier internet, boffins find

Published: 2021-01-30 00:10:32

Popularity: 60

Author: Thomas Claburn

Promising protocol much easier to fingerprint than HTTPS Google's QUIC (Quick UDP Internet Connections) protocol, announced in 2013 as a way to make the web faster, waited seven years before being implemented in the ad giant's Chrome browser. But it still arrived before privacy could get there.…

...more

Microsoft Edge goes homomorphic: Nobody will see your credentials... but you'll need to sign in to use it

Published: 2021-01-22 15:07:12

Popularity: 89

Author: Richard Speed

Has your password been pwned? MS browser will tell you Microsoft has detailed how the Password Monitor feature in Edge works after it pushed version 88 of the browser into the Stable channel.…

...more

ADT techie admits he peeked into women's home security cams thousands of times to watch them undress, have sex

Published: 2021-01-23 08:36:04

Popularity: 276

Author: Iain Thomson

Plus: SonicWall hacked, Qualcomm security wobble, warrantless cellphone monitoring by US snoops revealed In brief  One-time ADT security engineer Telesforo Aviles, 35, pleaded guilty to computer fraud in the US after spying on women through their home surveillance cameras.…

...more

Laptops given to British schools came preloaded with remote-access worm

Published: 2021-01-21 17:32:08

Popularity: 1762

Author: Gareth Corfield

Department for Education says: 'We believe this is not widespread' Updated  A shipment of laptops supplied to British schools by the Department for Education to help kids learn under lockdown came preloaded with malware, The Register can reveal.…

...more

Dnsmasq, used in only a million or more internet-facing devices globally, patches not-so-secret seven spoofing, hijacking flaws

Published: 2021-01-20 01:49:43

Popularity: 90

Author: Thomas Claburn

Get your updates when you can for gear from scores of manufacturers Seven vulnerabilities have been found in a popular DNS caching proxy and DHCP server known as dnsmasq, raising the possibility of widespread online attacks on networking devices.…

...more

Julian Assange will NOT be extradited to the US over WikiLeaks hacking and spy charges, rules British judge

Published: 2021-01-04 12:43:13

Popularity: 152

Author: Gareth Corfield

But it's not over yet: Next step is Uncle Sam's appeal to London's High Court Accused hacker and WikiLeaks founder Julian Assange should not be extradited to the US to stand trial, Westminster Magistrates' Court has ruled.…

...more

Hallowed Bugtraq infosec list killed then resurrected over the weekend: We heard your feedback, says Accenture

Published: 2021-01-18 07:05:11

Popularity: 85

Author: Iain Thomson

Plus: Watch out for NTFS-corrupting folder, Mimecast hack, and more In brief  Last week ended with news that the venerable infosec mailing list Bugtraq was being shutdown at the end of the month.…

...more

That's it. It's over. It's really over. From today, Adobe Flash Player no longer works. We're free. We can just leave

Published: 2021-01-12 01:41:14

Popularity: 1726

Author: Simon Sharwood

Post-Flashpocalypse, we stumble outside, hoping no one ever creates software as insecure as that ever again Adobe has finally and formally killed Flash.…

...more

Court orders encrypted email biz Tutanota to build a backdoor in user's mailbox, founder says 'this is absurd'

Published: 2020-12-08 21:07:13

Popularity: 167

Author: Gareth Corfield

Plus: Yet another UK.gov bod demands end-to-end encryption is broken Tutanota has been served with a court order to backdoor its encrypted email service – a situation founder Matthias Pfau described to The Register as "absurd."…

...more

We're not saying this is how SolarWinds was backdoored, but its FTP password 'leaked on GitHub in plaintext'

Published: 2020-12-16 00:00:12

Popularity: 918

Author: Thomas Claburn

'solarwinds123' won't inspire confidence, if true Updated  SolarWinds, the maker of the Orion network management software that was subverted to distribute backdoored updates that led to the compromise of multiple US government bodies, was apparently told last year that credentials for its software update server had been exposed in a public GitHub repo.…

...more

Oblivious DoH, OPAQUE passwords, Encrypted Client Hello: Cloudflare's protocol proposals to protect privacy

Published: 2020-12-08 18:45:07

Popularity: 42

Author: Tim Anderson

'Adopting these may have legal and policy implications' Web infrastructure company Cloudflare is pushing for the adoption of new internet protocols it says will enable a "privacy-respecting internet."…

...more

Zoom strong-armed by US watchdog to beef up security after boasting of end-to-end encryption that didn't exist

Published: 2020-11-09 21:03:32

Popularity: 256

Author: Kieren McCarthy

Vid-chat giant promises never again to make 'misrepresentations about its privacy and security practices' Zoom has been forced to agree to a range of security improvements in a settlement with America's consumer watchdog, the Federal Trade Commission, as a result of earlier wrongly claiming it offered true 256-bit end-to-end encryption.…

...more

And you thought Fuzzilli was a pasta... Google offers up $50k in cloud credits to fuzz the hell out of JavaScript engines

Published: 2020-10-02 22:50:38

Popularity: 58

Author: Shaun Nichols

And don't forget the paperwork after, says Chocolate Factory Google is offering bug hunters thousands of dollars worth of compute time on its cloud to hammer away at JavaScript engines and uncover new security flaws in the software.…

...more

IT guy whose job was to stop ex-staff running amok on the network is jailed for running amok on the network

Published: 2020-09-25 23:22:42

Popularity: 97

Author: Shaun Nichols

After he was demoted and fired, idiot logged into office PC from home and wiped storage systems An IT guy, who was tasked with locking out ex-employees from the company network, has been jailed after he logged in after being fired and wiped an office's computer storage drives.…

...more

Error-bnb: Techies scramble to fix Airbnb website bug that let strangers read each others' account messages

Published: 2020-09-26 00:06:57

Popularity: 104

Author: Shaun Nichols

LLM Says: ""oops, private""

One thing to let people rent your home, quite another to let them access your private comms Airbnb says it has fixed a baffling bug in its website that briefly caused some of its users to be shown messages belonging to others when viewing their account inboxes.…

...more

Amazon staffers took bribes, manipulated marketplace, leaked data including search algorithms – DoJ claims

Published: 2020-09-21 02:13:11

Popularity: 425

Author: Simon Sharwood

Banned merchants restored, rivals’ stores binned, cash sent around town in an Uber, it is alleged US prosecutors claim six people bribed corrupt Amazon insiders to rig the the web giant's Marketplace in their favor and leak terabytes of data including some search algorithms.…

...more

Good: US boasts it collared two in Chinese hacking bust. Bad: They aren't the actual hackers, rest are safe in China

Published: 2020-09-16 19:41:19

Popularity: 60

Author: Shaun Nichols

Ugly: And it's all about video game robberies at this stage Two people have been arrested in Malaysia as part of America's crackdown on the Chinese government's hackers.…

...more

Woman dies after hospital is unable to treat her during crippling ransomware infection, cops launch probe

Published: 2020-09-18 05:55:07

Popularity: 347

Author: Shaun Nichols

Extortionware is bad but it never killed anyo... never mind A woman in Germany died after a ransomware infection prevented her hospital from giving her emergency treatment.…

...more

Sigh. Another day, another reason for WordPress users to get patching: Hackers abuse bug in popular plugin

Published: 2020-09-03 23:20:48

Popularity: 61

Author: Thomas Claburn

Sites with WP File Manager should update ASAP – exploits in the wild A critical vulnerability in a popular WordPress plugin called WP File Manager was spotted on Tuesday and was quickly patched by the plugin's developers.…

...more

Court hearing on election security is zoombombed on 9/11 anniversary with porn, swastikas, pics of WTC attacks

Published: 2020-09-14 21:03:05

Popularity: 126

Author: Kieren McCarthy

Atlanta to upgrade software license with more protection, clerk tells us A court hearing on election security in America failed in its own security efforts – when it was zoombombed with porn, swastikas and images of the World Trade Center attacks.…

...more

Dunkin' Donuts drops some dough to glaze over lawsuit accusing it of covering up customer account hacks

Published: 2020-09-15 21:33:24

Popularity: 81

Author: Shaun Nichols

No way to sugarcoat this: New York AG eclairs the 2015 data theft matter settled Dunkin' Donuts today settled a lawsuit in which it was accused of hushing up the fact hackers siphoned its customers' personal information from its systems in 2015.…

...more

Worried about bootkits, rootkits, UEFI nasties? Have you tried turning on Secure Boot, asks the No Sh*! Agency

Published: 2020-09-16 00:40:36

Popularity: 116

Author: Shaun Nichols

And have you tried simply asking hackers to not hack? The NSA has published online a guide for IT admins to keep systems free of bootkits and rootkits.…

...more

Three middle-aged Dutch hackers slipped into Donald Trump's Twitter account days before 2016 US election

Published: 2020-09-11 09:07:10

Popularity: 1175

Author: Gareth Corfield

The Orange One was using a password breached four years previously Three “grumpy old hackers” in the Netherlands managed to access Donald Trump’s Twitter account in 2016 by extracting his password from the 2012 Linkedin hack.…

...more

Burn baby burn, plastic inferno! Infosec researchers turn 3D printers into self-immolating suicide machines

Published: 2020-07-31 10:15:09

Popularity: 323

Author: Gareth Corfield

Inflammatory findings from deadly serious investigation Some 3D printers can be flashed with firmware updates downloaded directly from the internet – and an infosec research firm says it has discovered a way to spoof those updates and potentially make the printer catch fire.…

...more

Capital One fined $80m for shoddy public cloud security. Yeah, same bank in that 106m customer-record hack

Published: 2020-08-07 01:22:24

Popularity: 72

Author: Katyanna Quach

All that money must be wired to the US Treasury immediately Capital One must pay a trivial $80m fine for its shoddy public cloud security – yes, the US banking giant that was hacked last year by a miscreant who stole personal information on 106 million credit-card applicants in America and Canada.…

...more

'We stopped ransomware' boasts Blackbaud CEO. And by 'stopped' he means 'got insurance to pay off crooks'

Published: 2020-08-03 14:02:22

Popularity: 64

Author: Gareth Corfield

CRM biz doesn't 'anticipate any kind of material financial impact' but can't say same for those whose data was nicked "We discovered and stopped a sophisticated attempted ransomware attack," Blackbaud CEO Michael Gianoni has told financial analysts – failing to mention the company simply paid off criminal extortionists to end the attack.…

...more

If you own one of these 45 Netgear devices, replace it: Kit maker won't patch vulnerable gear despite live proof-of-concept code

Published: 2020-07-30 11:28:36

Popularity: 2895

Author: Gareth Corfield

That's one way of speeding up the tech refresh cycle Netgear has quietly decided not to patch more than 40 home routers to plug a remote code execution vulnerability – despite security researchers having published proof-of-concept exploit code.…

...more

Twitter says spear-phishing attack hooked its staff and led to celebrity account hijack

Published: 2020-07-31 05:27:08

Popularity: 73

Author: Simon Sharwood

Attack came in waves that probed for staff with access to the creds crims craved Twitter has offered further explanation of the celebrity account hijack hack that saw 130 users’ timelines polluted with a Bitcoin scam.…

...more

We're suing Google for harvesting our personal info even though we opted out of Chrome sync – netizens

Published: 2020-07-28 19:40:18

Popularity: 114

Author: Thomas Claburn

Browser quitters say they'll return if web goliath lives up to privacy promises A handful of Chrome users have sued Google, accusing the browser maker of collecting personal information despite their decision not to sync data stored in Chrome with a Google Account.…

...more

Better get Grandpa off Windows 7 because zero-day bug in Zoom allows remote code execution on vintage OS

Published: 2020-07-13 11:50:07

Popularity: 84

Author: Iain Thomson

Plus: Kazakh man charged with corporate mega-hack, and more In brief  With world+dog on Zoom these days, news of a zero-day attack against the videoconferencing app would cause a stir, but relax – it's only if you're on Windows 7 or older.…

...more

Guilty: Russian miscreant who hacked LinkedIn, Dropbox, Formspring, stole 200-million-plus account records

Published: 2020-07-14 01:07:45

Popularity: 77

Author: Kieren McCarthy

Yevgeniy Nikulin faces up to 10 years in a US cooler The Russian hacker accused of raiding LinkedIn, Dropbox and Formspring, and obtaining data on 213 million user accounts, has been found guilty.…

...more

Digicert will shovel some 50,000 EV HTTPS certificates into the furnace this Saturday after audit bungle

Published: 2020-07-10 00:29:01

Popularity: 557

Author: Shaun Nichols

You've got less than 42 hours to regenerate your certs Digicert says, come Saturday, July 11, it will revoke tens of thousands of encryption certificates issued by intermediaries that were not properly audited.…

...more

You may be distracted by the pandemic but FYI: US Senate panel OK's backdoors-by-the-backdoor EARN IT Act

Published: 2020-07-06 20:42:17

Popularity: 2454

Author: Kieren McCarthy

Proposed Section 230 shake-up passes committee stage with amendments An amended version of America's controversial proposed EARN IT Act has been unanimously approved by the Senate Judiciary Committee – a key step in its journey to becoming law. This follows a series of changes and compromises that appear to address critics’ greatest concerns while introducing fresh problems.…

...more

Talk about the fox guarding the hen house. Comcast to handle DNS-over-HTTPS for Firefox-using subscribers

Published: 2020-06-26 01:07:13

Popularity: 171

Author: Shaun Nichols

Last November: These ISPs know too much! June: God bless the ISPs Comcast has agreed to be the first home broadband internet provider to handle secure DNS-over-HTTPS queries for Firefox browser users in the US, Mozilla has announced.…

...more

Boffins find that over nine out of ten 'ethical' hackers are being a bit naughty when it comes to cloud services

Published: 2020-06-17 06:57:04

Popularity: 94

Author: Thomas Claburn

Then again, cloud providers aren't exactly playing the smart game either Infosec pros and hackers regularly abuse cloud service providers to conduct reconnaissance and attacks, despite efforts by cloud providers to limit such activity.…

...more

Another month, another way to smash Intel's SGX security. Let's take a closer look at these latest holes...

Published: 2020-06-10 23:04:30

Popularity: 61

Author: Thomas Claburn

Plus: 10nm five-core 3GHz Lakefield system-on-chips announced Analysis  Intel's Software Guard Extensions, known as SGX among friends, consist of a set of instructions for running a secure enclave inside an encrypted memory partition using certain Intel microprocessors.…

...more

Update Firefox: Mozilla just patched three hijack-me holes and a bunch of other flaws

Published: 2020-06-04 02:28:12

Popularity: 112

Author: Shaun Nichols

Plus: Zoom fixes code-execution security bugs Mozilla has emitted security updates for Firefox to address eight CVE-listed security flaws, five of them considered to be high-risk vulnerabilities.…

...more

Zoom continues its catch-up security sprint with new training, bug bounty tweaks and promise of crypto playbook

Published: 2020-05-21 06:02:09

Popularity: 200

Author: Simon Sharwood

Sigh. How many users did it have before it started this stuff? Zoom has outlined more about its efforts to improve its security.…

...more

DNS this week stands for Drowning Needed Services: Design flaw in name server system can be exploited to flood machines offline

Published: 2020-05-21 10:52:04

Popularity: 78

Author: Shaun Nichols

Microsoft, BIND, Google, Cloudflare, Amazon, others fix up software or offer workarounds A new vulnerability has been found in the design of the world's domain-name system that potentially can be exploited to flood websites off the internet.…

...more

Zoom continues its catch-up security sprint with new training, bug bounty tweaks and promise of crypto playbook

Published: 2020-05-21 06:02:09

Popularity: 99

Author: Simon Sharwood

Sigh. How many users did it have before it started this stuff? Zoom has outlined more about its efforts to improve its security.…

...more

To test its security mid-pandemic, GitLab tried phishing its own work-from-home staff. 1 in 5 fell for it

Published: 2020-05-21 20:51:10

Popularity: 155

Author: Thomas Claburn

Welp, at least that's better than industry averages, says code-hosting biz Code hosting biz GitLab recently concluded a security exercise to test the susceptibility of its all-remote workforce to phishing – and a fifth of the participants submitted their credentials to the fake login page.…

...more

'iOS security is f**ked' says exploit broker Zerodium: Prices crash for taking a bite out of Apple's core tech

Published: 2020-05-14 10:31:11

Popularity: 706

Author: Thomas Claburn

LLM Says: "Apple hacked"

Million-dollar payouts zero out as hackers follow the money en masse Five years ago, Zerodium offered a $1m reward for a browser-based, untethered jailbreak in iOS 9. On Wednesday, the software exploit broker said it won't pay anything for some iOS bugs due to an oversupply.…

...more

Researchers spot thousands of Android apps leaking user data through misconfigured Firebase databases

Published: 2020-05-12 17:32:52

Popularity: 149

Author: Tim Anderson

Take care what data you enter into apps, it may be stored insecurely Security researchers at Comparitech have reported that an estimated 24,000 Android apps are leaking user data because of misconfigured Firebase databases.…

...more

IBM == Insecure Business Machines: No-auth remote root exec exploit in Data Risk Manager drops after Big Blue snubs bug report

Published: 2020-04-21 19:04:48

Popularity: 152

Author: Thomas Claburn

IT giant admits it made 'a process error, improper response' to flaw finder IBM has acknowledged that it mishandled a bug report that identified four vulnerabilities in its enterprise security software, and plans to issue an advisory.…

...more

Attack of the clones: If you were relying on older Xilinx FPGAs to keep your product's hardware code encrypted and secret, here's some bad news

Published: 2020-04-22 11:25:09

Popularity: 70

Author: Shaun Nichols

Decrypted configuration bitstream can be siphoned from chips via side-channel flaw A newly disclosed vulnerability in older Xilinx FPGAs can be exploited to simplify the process of extracting and decrypting the encrypted bitstreams used to configure the chips.…

...more

GCC 10 gets security bug trap. And look what just fell into it: OpenSSL and a prod-of-death flaw in servers and apps

Published: 2020-04-23 10:06:12

Popularity: 110

Author: Shaun Nichols

Static analyzer proves its worth with discovery of null-pointer error A static analysis feature set to appear in GCC 10, which will catch common programming errors that can lead to security vulnerabilities, has scored an early win – it snared an exploitable flaw in OpenSSL.…

...more

NSO Group: Facebook tried to license our spyware to snoop on its own addicts – the same spyware it's suing us over

Published: 2020-04-03 21:37:31

Popularity: 197

Author: Shaun Nichols

Antisocial network sought surveillance tech to boost its creepy Onavo Protect app, it is claimed NSO Group – sued by Facebook for developing Pegasus spyware that targeted WhatsApp users – this week claimed Facebook tried to license the very same surveillance software to snoop on its own social-media addicts.…

...more

Zoom's end-to-end encryption isn't actually end-to-end at all. Good thing the PM isn't using it for Cabinet calls. Oh, for f...

Published: 2020-04-01 05:11:05

Popularity: 4537

Author: Kieren McCarthy

Super-crypto actually normal TLS, lawsuit launched over Facebook API usage, privacy policy rewritten UK Prime Minister Boris Johnson sparked security concerns on Tuesday when he shared a screenshot of “the first ever digital Cabinet” on his Twitter feed. It revealed the country’s most senior officials and ministers were using bog-standard Zoom to discuss critical issues facing Blighty.…

...more

Fancy that: Hacking airliner systems doesn't make them magically fall out of the sky

Published: 2020-03-04 11:30:10

Popularity: 131

Author: Gareth Corfield

Study finds most A320 pilots shrug, ignore dodgy systems and land safely Airline pilots faced with hacked or spoofed safety systems tend to ignore them – but could cost their airlines big sums of money, an infosec study has found.…

...more

It has been 15 years, and we're still reporting homograph attacks – web domains that stealthily use non-Latin characters to appear legit

Published: 2020-03-04 14:00:14

Popularity: 136

Author: Shaun Nichols

More than a dozen dodgy websites spotted masquerading as the real deal, HTTPS certs and all What's old is new again as infosec bods are sounding the alarm over a fresh wave of homoglyph characters being used to lure victims to malicious fake websites.…

...more

Download this update from mybrowser.microsoft.com. Oh, sorry, that was malware on a hijacked sub-domain. Oops

Published: 2020-03-04 19:04:06

Popularity: 243

Author: Shaun Nichols

Lax DNS leaves door wide open for miscreants to impersonate Windows giant on its own websites If you saw a link to mybrowser.microsoft.com, would you have trusted it? Downloaded and installed an Edge update from it? How about identityhelp.microsoft.com to change your password?…

...more

Alleged Vault 7 leaker trial finale: Want to know the CIA's password for its top-secret hacking tools? 123ABCdef

Published: 2020-03-05 00:47:25

Popularity: 1920

Author: Kieren McCarthy

Tales of terrible security, poor compartmentalization, and more, emerge from the Schulte hearings Analysis  The fate of the man accused of leaking top-secret CIA hacking tools – software that gave the American spy agency access to targets' phones and computer across the world – is now in the hands of a jury. And, friend, do they have their work cut out for them.…

...more

Let's Encrypt? Let's revoke 3 million HTTPS certificates on Wednesday, more like: Check code loop blunder strikes

Published: 2020-03-03 19:44:53

Popularity: 1160

Author: Thomas Claburn

Tons of TLS certs need to be tossed immediately after Go snafu On Wednesday, March 4, Let's Encrypt – the free, automated digital certificate authority – will briefly become Let's Revoke, to undo the issuance of more than three million flawed HTTPS certs.…

...more

Departing MI5 chief: Break chat app crypto for us, kthxbai

Published: 2020-02-26 17:17:13

Popularity: 62

Author: Gareth Corfield

Sir Andrew Parker also claims UK spies are not doing bulk surveillance British spies are once again stipulating that tech companies break their encryption so life is made easier for state-sponsored eavesdroppers.…

...more

After blowing $100m to snoop on Americans' phone call logs for four years, what did the NSA get? Just one lead

Published: 2020-02-26 22:29:11

Popularity: 319

Author: Kieren McCarthy

Section 215 more useless than we suspected yet they still want to keep it The controversial surveillance program that gave the NSA access to the phone call records of millions of Americans has cost US taxpayers $100m – and resulted in just one useful lead over four years.…

...more

Mind the gap: Google patches holes in Chrome – exploit already out there for one of them after duo spot code fix

Published: 2020-02-25 21:22:19

Popularity: 88

Author: Thomas Claburn

Pair engineer malicious code from public source tweak before official binary releases Google has updated Chrome for Linux, Mac, and Windows to address three security vulnerabilities – and exploit code for one of them is already public, so get patching.…

...more

Voatz of no confidence: MIT boffins eviscerate US election app, claim fiends could exploit flaws to derail democracy

Published: 2020-02-13 21:58:19

Popularity: 78

Author: Thomas Claburn

Shoddy code allegations are just FUD, software maker insists Only a week after the mobile app meltdown in Iowa's Democratic Caucus, computer scientists at MIT have revealed their analysis of the Voatz app used in West Virginia's 2018 midterm election.…

...more

Remember those infosec fellas who were cuffed while testing the physical security of a courthouse? The burglary charges have been dropped

Published: 2020-01-31 20:39:31

Popularity: 116

Author: Shaun Nichols

And it only took, er, four and a half months for people to see sense Criminal charges have been dropped against two infosec professionals who were arrested during a sanctioned physical penetration test gone wrong.…

...more

Google halts paid-for Chrome extension updates amid fraud surge: Web Store in lockdown 'due to the scale of abuse'

Published: 2020-01-27 19:58:06

Popularity: 83

Author: Thomas Claburn

Meanwhile, probe reveals how Avast's 'anonymized' user data can be, er, deanonymized On Saturday, Google temporarily disabled the ability to publish paid Chrome apps, extensions, and themes in the Chrome Web Store due to a surge in fraud.…

...more

Hospital hacker spared prison after plod find almost 9,000 cardiac images at his home

Published: 2020-01-20 11:30:47

Popularity: 165

Author: Gareth Corfield

NHS working with cops and ICO to determine if patients must be told A Stoke-on-Trent hospital administrator has avoided prison after hacking his NHS trust and helping himself to almost 9,000 heart scan images.…

...more

Who honestly has a crown prince in their threat model? UN report officially fingers Saudi royal as Bezos hacker

Published: 2020-01-22 23:13:01

Popularity: 74

Author: Kieren McCarthy

Rapporteurs call for investigation, technical security report leaks The Crown Prince of Saudi Arabia, Mohammad bin Salman, has been officially fingered as the man responsible for hacking Amazon CEO Jeff Bezos’s iPhone X, causing a massive stir in diplomatic circles.…

...more

WTF, EFS? Experts warn Windows encryption could spawn nasty new ransomware

Published: 2020-01-21 14:00:12

Popularity: 158

Author: Shaun Nichols

Redmond's own security tools could be abused by hard-to-block file-scrambling software nasties The encryption technology Microsoft uses to protect Windows file systems can be exploited by ransomware.…

...more

Crown Prince of Saudi Arabia accused of hacking Jeff Bezos' phone with malware-laden WhatsApp message

Published: 2020-01-22 00:31:35

Popularity: 360

Author: Kieren McCarthy

Mid-East nation slams 'absurd' claim, UN report to emerge Updated  Candid pictures used to threaten Amazon boss Jeff Bezos were exposed not by his current paramour's brother, as some believe, but through a sophisticated hacking operation personally directed by the crown prince of Saudi Arabia, Mohammad bin Salman, The Guardian suggests.…

...more

Updated your WordPress plugins lately? Here are 320,000 auth-bypassing reasons why you should

Published: 2020-01-15 00:15:55

Popularity: 233

Author: Shaun Nichols

Another day, another critical set of flaws A pair of widely used WordPress plugins need to be patched on more than 320,000 websites to close down vulnerabilities that can be exploited to gain admin control of the web publishing software.…

...more

Yo, sysadmins! Thought Patch Tuesday was big? Oracle says 'hold my Java' with huge 334 security flaw fix bundle

Published: 2020-01-15 21:33:00

Popularity: 103

Author: Shaun Nichols

House of Larry delivers massive update for 93 products Oracle has released a sweeping set of security patches across the breadth of its software line.…

...more

Bad news: Windows security cert SNAFU exploits are all over the web now. Also bad: Citrix gateway hole mitigations don't work for older kit

Published: 2020-01-16 23:13:09

Popularity: 587

Author: Shaun Nichols

Good news: There is none. Well, apart from you can at least fully patch the Microsoft blunder Vid  Easy-to-use exploits have emerged online for two high-profile security vulnerabilities, namely the Windows certificate spoofing bug and the Citrix VPN gateway hole. If you haven't taken mitigation steps by now, you're about to have a bad time.…

...more

'Friendly' hackers are seemingly fixing the Citrix server hole – and leaving a nasty present behind

Published: 2020-01-17 19:49:15

Popularity: 44

Author: Shaun Nichols

LLM Says: "Nasty surprise"

Congratulations, you've won a secret backdoor Hackers exploiting the high-profile Citrix CVE-2019-19781 flaw to compromise VPN gateways are now patching the servers to keep others out.…

...more

Wheelie bad end to 2019 for Canyon Bicycles as hackers puncture IT systems

Published: 2020-01-07 13:30:13

Popularity: 40

Author: Paul Kunert

CEO confirms servers, software locked by perps German cycle-maker Canyon Bicycles GmbH has confirmed it was the victim of a security break-in over the holiday period that has all the hallmarks of a ransomware attack with parts of the infrastructure padlocked by the perpetrators.…

...more

New year, new critical Cisco patches to install – this time for a dirty dozen of bugs that can be exploited to sidestep auth, inject commands, etc

Published: 2020-01-03 20:10:45

Popularity: 95

Author: Shaun Nichols

Data Center Network Manager bugapalooza with three must-fix flaws Cisco is kicking off 2020 with the release of a crop of patches for its Data Center Network Manager.…

...more

It's time you were T0RTT a lesson: Here's how you could build a better Tor, say boffins

Published: 2019-12-12 11:16:04

Popularity: 72

Author: Shaun Nichols

Uni brains pitch smart math for speeding up establishment of circuits in anonymizing onion network Academics in Germany say they've found a way to make Tor and similar onion networks more efficient and lower their latency.…

...more

It's the end of the 20-teens, and your Windows PC can still be pwned by nothing more than a simple bad font

Published: 2019-12-10 22:33:00

Popularity: 110

Author: Shaun Nichols

End 2019 with a Patch Tuesday from Microsoft, Adobe, SAP and Intel With the year winding to a close and the holiday parties set to kick off, admins will want to check out the December Patch Tuesday load from Microsoft, Adobe, Intel, and SAP and get them installed before downing the first of many egg nogs.…

...more

How to fool infosec wonks into pinning a cyber attack on China, Russia, Iran, whomever

Published: 2019-12-05 15:44:04

Popularity: 120

Author: Gareth Corfield

Learning points, not an instruction manual Black Hat Europe  Faking digital evidence during a cyber attack – planting a false flag – is simple if you know how, as noted infosec veteran Jake Williams told London's Black Hat Europe conference.…

...more

Feds slap $5m bounty on 'Evil Corp' Russian duo accused of running ZeuS, Dridex banking trojans

Published: 2019-12-05 16:49:22

Popularity: 82

Author: Gareth Corfield

Account-draining malware masterminds charged but remain in motherland US prosecutors have slapped a $5m bounty on the heads of two Russian nationals they claim are part of the malware gang behind the banking trojans ZeuS and Dridex.…

...more

If there's somethin' stored in a secure enclave, who ya gonna call? Membuster!

Published: 2019-12-05 22:22:19

Popularity: 153

Author: Thomas Claburn

Boffins ride the memory bus past Intel's SGX to your data Computer scientists from UC Berkeley, Texas A&M, and semiconductor biz SK Hynix have found a way to defeat secure enclave protections by observing memory requests from a CPU to off-chip DRAM through the memory bus.…

...more

Don't pay off Ryuk ransomware, warn infoseccers: Its creators borked the decryptor

Published: 2019-12-10 16:30:11

Popularity: 299

Author: Gareth Corfield

Oracle DBs particularly vulnerable to fake decryptions, say researchers If you're an Oracle database user and are tempted to pay off a Ryuk ransomware infection to get your files back, for pity's sake, don't. The criminals behind it have broken their own decryptor, meaning nobody will be able to unlock files scrambled by the malicious software.…

...more

Intel might want to reconsider the G part of SGX – because it's been plunderstruck

Published: 2019-12-10 18:00:07

Popularity: 60

Author: Thomas Claburn

I was caught in the middle of a memory attack, and I knew there was no turning back Intel on Tuesday plans to release 11 security advisories, including a microcode firmware update to patch a vulnerability in its Software Guard Extensions (SGX) on recent Core microprocessors that allows a privileged attacker to corrupt SGX enclave computations.…

...more

Tricky VPN-busting bug lurks in iOS, Android, Linux distros, macOS, FreeBSD, OpenBSD, say university eggheads

Published: 2019-12-06 05:01:06

Popularity: 108

Author: Shaun Nichols

OpenVPN, WireGuard, IKEv2/IPSec also vulnerable to tampering flaw, we're told A bug in the way Unix-flavored systems handle TCP connections could put VPN users at risk of having their encrypted traffic hijacked, it is claimed.…

...more

China fires up 'Great Cannon' denial-of-service blaster, points it toward Hong Kong

Published: 2019-12-06 20:07:05

Popularity: 362

Author: Shaun Nichols

Protest organizers come under fire from network traffic barrage China is reportedly using the 'cannon' capabilities of its massive domestic internet to try and take down anti-government websites in Hong Kong.…

...more

Time to check who left their database open and leaked 7.5m customer records: Hi there, Adobe Creative Cloud!

Published: 2019-10-25 19:13:17

Popularity: 550

Author: Shaun Nichols

No passwords, banking details, but enough info to convincingly phish someone Adobe has pulled offline a public-facing poorly secured Elasticsearch database containing information on 7.5 million Creative Cloud customers.…

...more

Row erupts over who to blame after NordVPN says: One of our servers was hacked via remote management tool

Published: 2019-10-21 21:44:15

Popularity: 202

Author: Shaun Nichols

Netizens' traffic flowing out of box could have been sniffed by miscreants Analysis  NordVPN spent today attempting to downplay a security breach in which someone sneaked into one of its servers for purposes unknown.…

...more

Apple insists it's totally not doing that thing it wasn't accused of: We're not handing over Safari URLs to Tencent – just people's IP addresses

Published: 2019-10-14 20:05:40

Popularity: 605

Author: Thomas Claburn

Cupertino in China Syndrome meltdown Responding to concern that its Safari browser's defense against malicious websites may reveal the IP addresses of some users' devices to China-based Tencent, Apple insists that Safari doesn't reveal a different bit of information, the webpages Safari users visit.…

...more

Sudo? More like Su-doh: There's a fun bug that gives restricted sudoers root access (if your config is non-standard)

Published: 2019-10-14 21:14:36

Popularity: 235

Author: Chris Williams

All it takes is -u#-1 ... Wh%& t#e fsck*? It's only Monday, and we already have a contender for the bug of the week.…

...more

Here we go again: US govt tells Facebook to kill end-to-end encryption for the sake of the children

Published: 2019-10-04 19:15:52

Popularity: 728

Author: Shaun Nichols

Uncle Sam calls on tech giants to open up platforms for government snooping The US government is renewing its efforts to talk tech firms out of using end-to-end encryption methods that would keep police from snooping on conversations.…

...more

Google sounds the alarm over Android flaw being exploited in the wild, possibly by NSO

Published: 2019-10-04 21:07:50

Popularity: 184

Author: Shaun Nichols

Pixel, S-Series, Moto Z3 among vulnerable gear Google is warning owners of some popular Android devices to keep a close eye on their gear following the release of an exploit for an unpatched flaw.…

...more

How much pass could LastPass pass if LastPass passed last pass? Login-leaking security hole fixed

Published: 2019-09-16 19:36:04

Popularity: 187

Author: Shaun Nichols

Update now to stop webpages snooping on recently used credentials LastPass has fixed a security bug that potentially allowed malicious websites to obtain the username and passphrase inserted by the password manager on the previously visited site.…

...more

Dear Planet Earth: Patch Webmin now – zero-day exploit emerges for potential hijack hole in server control panel

Published: 2019-08-19 20:28:13

Popularity: 49

Author: Thomas Claburn

Flawed code traced to home build system, vulnerability can be attacked in certain configs Updated  The maintainers of Webmin – an open-source application for system-administration tasks on Unix-flavored systems – have released Webmin version 1.930 and the related Usermin version 1.780 to patch a vulnerability that can be exploited to achieve remote code execution in certain configurations.…

...more

No REST for the wicked: Ruby gem hacked to siphon passwords, secrets from web devs

Published: 2019-08-20 21:21:17

Popularity: 68

Author: Thomas Claburn

Developer account cracked due to credential reuse, source tampered with and released to hundreds of programmers An old version of a Ruby software package called rest-client that was modified and released about a week ago has been removed from the Ruby Gems repository – because it was found to be deliberately leaking victims' credentials to a remote server.…

...more

Exim marks the spot… of remote code execution: Patch due out today for 'give me root' flaw in mail server

Published: 2019-09-06 10:00:13

Popularity: 65

Author: Shaun Nichols

Install incoming update to avoid having your boxes hijacked The widely used Exim email server software is due to be patched today to close a critical security flaw that can be exploited to potentially gain root-level access to the machine.…

...more

Biz forked out $115k to tout 'Time AI' crypto at Black Hat. Now it sues organizers because hackers heckled it

Published: 2019-08-26 08:02:06

Popularity: 89

Author: Thomas Claburn

Lawsuit argues event bosses breached deal by failing to prevent audience hostility Crown Sterling, a Newport Beach, California-based biz that calls itself "a leading digital cryptographic firm," is suing UBM, the UK-based owner of the Black Hat USA conference, in America for allegedly violating its sponsorship agreement.…

...more

Breaking news: Apple un-breaks break on jailbreak break

Published: 2019-08-26 23:38:29

Popularity: 91

Author: Shaun Nichols

The fix for the fix is in Apple has issued an update to address a potentially serious security flaw it re-opened in the latest version of iOS.…

...more

Capital One 'hacker' hit with fresh charges: She burgled 30 other AWS-hosted orgs, Feds claim

Published: 2019-08-29 20:02:28

Popularity: 72

Author: Kieren McCarthy

Ex-Amazon techie accused of cyber-looting other storage buckets, mining crypto-coins on hacked servers The ex-Amazon engineer who allegedly stole 100 million Capital One credit applicants' personal details from AWS cloud buckets has been formally accused of swiping data from 30 other organizations.…

...more

JACK OF ALL TIRADES: Twitter boss loses account to cunning foul-mouthed pranksters

Published: 2019-08-31 10:01:07

Popularity: 46

Author: Shaun Nichols

Plus a Cisco bug, dentists bitten by malware, and France takes down a worm Roundup  This week ended with a bang, thanks to some Twitter hackers.…

...more

NSA asks Congress to permanently reauthorize spying program that was so shambolic, the snoops had shut it down

Published: 2019-08-16 20:09:44

Popularity: 243

Author: Kieren McCarthy

You never know, we might figure out how not to screw up in future Analysis  In the clearest possible sign that the US intelligence services live within their own political bubble, the director of national intelligence has asked Congress to reauthorize a spying program that the NSA itself decided to shut down after it repeatedly – and illegally – gathered the call records of millions of innocent Americans.…

...more

WTF is Boeing on? Not just customer databases lying around on the web. 787 jetliner code, too, security bugs and all

Published: 2019-08-08 06:56:13

Popularity: 999

Author: Iain Thomson

Fears of cyber-hijackings? That's plane crazy, says Dreamliner maker Black Hat  A Black Hat presentation on how to potentially hijack a 787 – by exploiting bugs found in internal code left lying around on a public-facing server – was last night slammed as "irresponsible and misleading" by Boeing.…

...more

HTTP/2, Brute! Then fall, server. Admin! Ops! The server is dead

Published: 2019-08-14 09:02:08

Popularity: 84

Author: Thomas Claburn

Beware the denials of service: Netflix warns of eight networking bugs On Tuesday, Netflix, working in conjunction with Google and CERT/CC, published a security advisory covering a series of vulnerabilities that enable denial of service attacks against servers running HTTP/2 services.…

...more

Dear hackers: If you try to pwn a website for phishing, make sure it's not the personal domain of a senior Akamai security researcher

Published: 2019-07-29 12:00:09

Popularity: 532

Author: Shaun Nichols

Crooks fail to hijack infosec bloke's site to dress it up as a legit Euro bank login page Exclusive  Think you have bad luck? Imagine being the script kiddie who inadvertently tried and failed to pwn an Akamai security pro.…

...more

Backdoors won't weaken your encryption, wails FBI boss. And he's right. They won't – they'll fscking torpedo it

Published: 2019-07-25 20:18:28

Popularity: 762

Author: Iain Thomson

Give it a Wray, give it a Wray, give it a Wray now: Big Chris steps in to defend blowing a hole in personal crypto FBI head honcho Christopher Wray is rather peeved that you all think the US government is trying to weaken cryptography, privacy, and online security, by demanding backdoors in encryption software.…

...more

In the cooler for the next three years: Hacker of iCloud accounts used by athletes and rappers

Published: 2019-07-19 23:58:06

Popularity: 124

Author: Thomas Claburn

Phishing led to shopping spree with victims' credit cards A man from the US state of Georgia who pleaded guilty in March to breaking into the Apple iCloud accounts of sports and entertainment figures was sentenced on Thursday to three years and one month in federal prison – and ordered to pay almost $700,000 in restitution.…

...more

It's 2019 and you can still pwn an iPhone with a website: Apple patches up iOS, Mac bugs in July security hole dump

Published: 2019-07-23 01:52:06

Popularity: 173

Author: Shaun Nichols

LLM Says: "Pwned again"

20 WebKit flaws among latest batch of bug fixes On Monday Apple released a fresh round of security fixes for a load of its operating systems and applications.…

...more

Israel's NSO Group: Our malware? Slurp your cloud backups plus phone data? They've misunderstood

Published: 2019-07-19 17:00:07

Popularity: 186

Author: Gareth Corfield

After report claimed its sales pitches boasted of doing that Israeli spyware firm NSO Group has denied it developed malware that can steal user data from cloud services run by Amazon, Apple, Facebook, Google and Microsoft.…

...more

Patch now before you get your NAS kicked: Iomega storage boxes leave millions of files open to the internet

Published: 2019-07-16 13:00:13

Popularity: 229

Author: Shaun Nichols

API blunder exposes data, fix incoming from Lenovo Lenovo is emitting an emergency firmware patch for Iomega NAS devices after the network-attached storage boxes were discovered inadvertently offering millions of files to the internet via an insecure software interface.…

...more

Malicious code ousted from PureScript's npm installer – but who put it there in the first place?

Published: 2019-07-15 06:04:06

Popularity: 108

Author: Thomas Claburn

Account hijacking claimed by some but it may just be a developer behaving badly Another JavaScript package in the npm registry - the installer for PureScript - has been tampered with, leading project maintainers to revise their software to purge the malicious code.…

...more

Two pentesters, one glitch: Firefox browser menaced by ancient file-snaffling bug, er, feature

Published: 2019-07-09 11:00:04

Popularity: 88

Author: Richard Speed

Forgive the sins of the fathers: Mozilla to have another go at tackling teenage flaw Mozilla has been sitting on a new variant of an age-old flaw for almost a year, even with public disclosure happening back in January.…

...more

We are shocked to learn oppressive authoritarian surveillance state China injects spyware into foreigners' smartphones

Published: 2019-07-02 19:55:52

Popularity: 366

Author: Shaun Nichols

Border cops accused of loading tourists' mobiles up with snoop app in Muslim area Authorities in a tumultuous region of China are ordering tourists and other visitors to install spyware on their smartphones, it is claimed.…

...more

White House mulls just banning strong end-to-end crypto. Plus: More bad stuff in infosec land

Published: 2019-07-01 05:57:06

Popularity: 119

Author: Shaun Nichols

We'll be over there bashing our head on the wall while you read this Roundup  As June turns over to July, here are some additional bits of security news besides our regular infosec coverage.…

...more

Cop a load of this: 1TB of police body camera videos found lounging around public databases

Published: 2019-07-01 22:18:59

Popularity: 332

Author: Thomas Claburn

Miscreants grabbed sensitive footage belonging to officers in Miami, elsewhere, it is feared In yet another example of absent security controls, troves of police body camera footage were left open to the world for anyone to siphon off, according to an infosec biz.…

...more

July is here – and so are the latest Android security fixes. Plenty of critical updates for all

Published: 2019-07-01 23:20:09

Popularity: 147

Author: Shaun Nichols

Patch, punch, it's the first of the month Google today posted a fresh round of Android security fixes.…

...more

Iran's blame-it-on-Bitcoin 'leccy shortage probably isn't a US hack cover story... yet

Published: 2019-06-28 18:45:48

Popularity: 99

Author: Gareth Corfield

But just imagine Stuxnet: Consumer Edition Comment  Iran claims that recent surges in electricity demand, leading to blackouts and brownouts, were caused by too many cryptocurrency miners’ power-hungry machines being hooked up to the national grid – though all may not be as it seems.…

...more

2001: Linux is cancer, says Microsoft. 2019: Hey friends, ah, can we join the official linux-distros mailing list, plz?

Published: 2019-06-27 19:13:32

Popularity: 1477

Author: Richard Speed

Windows giant cheered on by Linux Foundation as it seeks membership of private security-focused message board Microsoft's transformation into a fully paid-up member of the Linux love-train continued this week as the Windows giant sought to join the exclusive club that is the official linux-distros mailing list.…

...more

Millions of Windows Dell PCs need patching: Give-me-admin security gremlin found lurking in bundled support tool

Published: 2019-06-20 22:21:53

Popularity: 316

Author: Shaun Nichols

Can't spell SupportAssist without 'ass' and 'u' – other makers may be hit, too Updated  Dell's troubleshooting software SupportAssist, bundled with the US tech titan's home and business computers, has a security flaw that can be exploited by malware and rogue logged-in users to gain administrator powers.…

...more

Iran is doing to our networks what it did to our spy drone, claims Uncle Sam: Now they're bombing our hard drives

Published: 2019-06-24 19:35:43

Popularity: 536

Author: Shaun Nichols

Tehran's hackers are 'wiping' infected machines as tensions spike, fresh sanctions approved Hackers operating on behalf of the Iranian government have turned destructive, the US Department of Homeland Security has claimed.…

...more

What the cell...? Telcos around the world were so severely pwned, they didn't notice the hackers setting up VPN points

Published: 2019-06-25 03:18:05

Popularity: 94

Author: Shaun Nichols

Revealed: Long-running espionage campaign targets phone carriers to snoop on VIPs' location, call records Hackers infiltrated the networks of at least ten cellular telcos around the world, and remained hidden for years, as part of a long-running tightly targeted surveillance operation, The Register has learned. This espionage campaign is still ongoing, it is claimed.…

...more

Spin the wheel and find today's leaky cloud DB... *clack clack... clack* A huge trove of medical malpractice complaints

Published: 2019-06-18 22:58:11

Popularity: 84

Author: Shaun Nichols

150,000 personal records on people, including US veterans, upset with their healthcare In what has become a depressingly common occurrence, the personal information of hundreds of thousands of people may have fallen into the wrong hands because yet another organization did not secure a cloud-hosted database.…

...more

Black Hat USA axes anti-abortion congressman as keynote speaker after outcry – and more news from infosec land

Published: 2019-06-15 07:25:06

Popularity: 120

Author: Shaun Nichols

Your quick guide to hacks, patches and scandal Roundup  Here's a quick roundup of recent infosec news beyond what we've already reported.…

...more

Yubico YubiKey lets you be me: Security blunder sparks recall of govt-friendly auth tokens

Published: 2019-06-13 21:57:06

Popularity: 95

Author: Shaun Nichols

For FIPS sake! Yubico is recalling one of its YubiKey lines after the authentication dongles were found to have a security weakness.…

...more

Telegram CEO calls out rival Signal, claiming it has ties to US government

Published: 2024-05-14 14:30:13

Popularity: 24

Author: Matthew Connatser

Drama between two of the leading secure messaging services Telegram CEO Pavel Durov issued a scathing criticism of Signal, alleging the messaging service is not secure and has ties to US intelligence agencies.…

...more

Iran most likely to launch destructive cyber-attack against US – ex-Air Force intel analyst

Published: 2024-05-10 21:01:07

Popularity: 13

Author: Jessica Lyons

But China's the most technologically advanced Interview  China remains the biggest cyber threat to the US government, America's critical infrastructure, and its private-sector networks, the nation's intelligence community has assessed.…

...more

Dropbox dropped the ball on security, haemorrhaging customer and third-party info

Published: 2024-05-02 00:58:10

Popularity: 18

Author: Simon Sharwood

Only from its digital doc-signing service, which is isolated from its cloudy storage Dropbox has revealed a major attack on its systems that saw customers' personal information accessed by unknown and unauthorized entities.…

...more

Infosec biz boss accused of BS'ing the world about his career, anti-crime product, customers

Published: 2024-05-01 18:58:08

Popularity: 14

Author: Jessica Lyons

Intrusion investors went through Blount farce trauma, says SEC Jack Blount, the now-ex CEO of Intrusion, has settled with the SEC over allegations he made false and misleading statements about his infosec firm's product as well as his own background and experience.…

...more

Flaws in Chinese keyboard apps leave 750 million users open to snooping, researchers claim

Published: 2024-04-26 05:33:17

Popularity: 27

Author: Simon Sharwood

Huawei is OK, but Xiaomi, OPPO, and Samsung are in strife. And Honor isn't living its name Many Chinese keyboard apps, some from major handset manufacturers, can leak keystrokes to determined snoopers, leaving perhaps three quarters of a billion people at risk according to research from the University of Toronto’s Citizen Lab.…

...more

Management company settles for $18.4M after nuclear weapons plant staff fudged their timesheets

Published: 2024-04-24 15:00:09

Popularity: 9

Author: Connor Jones

The firm 'fessed up to staff misconduct and avoided criminal liability A company contracted to manage an Amarillo, Texas nuclear weapons facility has to pay US government $18.4 million in a settlement over allegations that its atomic technicians fudged their timesheets to collect more money from Uncle Sam.…

...more

Critical Fluent Bit bug affects all major cloud providers, say researchers

Published: 2024-05-21 17:45:15

Popularity: 17

Author: Connor Jones

Crashes galore, plus especially crafty crims could use it for much worse Infosec researchers are alerting the industry to a critical vulnerability in Fluent Bit – a logging component used by a swathe of blue chip companies and all three major cloud providers.…

...more

Command senior chief busted for secretly setting up Wi-Fi on US Navy combat ship

Published: 2024-06-04 20:04:06

Popularity: 58

Author: Matthew Connatser

LLM Says: ""Sneaky sailor""

In the Navy, no, you cannot have an unauthorized WLAN. In the Navy, no, that's not a good plan The US Navy has cracked down on an illicit Wi-Fi network installed on a combat ship by demoting the senior enlisted leader who ordered it to be set up.…

...more

OpenSSF sings a Siren song to steer developers away from buggy FOSS

Published: 2024-05-20 23:06:10

Popularity: 11

Author: Brandon Vigliarolo

LLM Says: "Siren song of bugs"

New infosec intelligence service aims to spread the word about recently discovered vulns in free code Securing open source software may soon become a little bit easier thanks to a new vulnerability info-sharing effort initiated by the Open Source Security Foundation (OpenSSF).…

...more

GitHub Enterprise Server patches 10-outta-10 critical hole

Published: 2024-05-22 07:31:09

Popularity: 14

Author: Matthew Connatser

LLM Says: "Critical fail 🔥👀"

On the bright side, someone made up to $30,000+ for finding it GitHub has patched its Enterprise Server software to fix a security flaw that scored a 10 out of 10 CVSS severity score.…

...more

'China-aligned' spyware slingers operating since 2018 unmasked at last

Published: 2024-05-23 03:47:12

Popularity: 12

Author: Matthew Connatser

LLM Says: "spies outed"

Unfading Sea Haze adept at staying under the radar Bitdefender says it has tracked down and exposed an online gang that has been operating since 2018 nearly without a trace – and likely working for Chinese interests.…

...more

Suspected supply chain attack backdoors courtroom recording software

Published: 2024-05-24 20:29:11

Popularity: 10

Author: Connor Jones

LLM Says: ""Backdoored audio""

An open and shut case, but the perps remain at large – whoever they are Justice is served… or should that be saved now that audio-visual software deployed in more than 10,000 courtrooms is once again secure after researchers uncovered evidence that it had been backdoored for weeks.…

...more

Release the hounds! Securing datacenters may soon need sniffer dogs

Published: 2024-07-18 00:54:10

Popularity: 7

Author: Simon Sharwood

LLM Says: "Sniff out security"

Nothing else can detect attackers with implants designed to foil physical security Sniffer dogs may soon become a useful means of improving physical security in datacenters, as increasing numbers of people are adopting implants like NFC chips that have the potential to enable novel attacks on access control tools.…

...more

Kaspersky challenges US government to put up or shut up about Kremlin ties

Published: 2024-07-18 16:29:05

Popularity: 30

Author: Jessica Lyons

LLM Says: ""Bring it on!""

Stick an independent probe in our software, you won't find any Putin.DLL backdoor Kaspersky has hit back after the US government banned its products – by proposing an independent verification that its software is above board and not backdoored by the Kremlin.…

...more

CrowdStrike's Falcon Sensor also linked to Linux kernel panics and crashes

Published: 2024-07-21 23:51:18

Popularity: 182

Author: Simon Sharwood

LLM Says: "System Crash"

Rapid restore tool being tested as Microsoft estimates 8.5M machines went down Updated  CrowdStrike's now-infamous Falcon Sensor software, which last week led to widespread outages of Windows-powered computers, has also been linked to crashes of Linux machines.…

...more

Alphabet's reported $23B bet on Wiz fizzles out

Published: 2024-07-23 14:32:12

Popularity: 10

Author: Richard Speed

LLM Says: "Fizzing out"

Cybersecurity outfit to go its own way to IPO and $1B ARR On the day of Alphabet's Q2 earnings call, cybersecurity firm Wiz has walked from a $23 billion takeover bid by Google's parent company.…

...more

Patch management still seemingly abysmal because no one wants the job

Published: 2024-07-25 07:27:06

Popularity: 10

Author: Brandon Vigliarolo

LLM Says: "No one wants the task"

Are your security and ops teams fighting to pass the buck? Comment  Patching: The bane of every IT professional's existence. It's a thankless, laborious job that no one wants to do, goes unappreciated when it interrupts work, and yet it's more critical than ever in this modern threat landscape.…

...more

Kaspersky says Uncle Sam snubbed proposal to open up its code for third-party review

Published: 2024-07-25 12:01:14

Popularity: 10

Author: Jessica Lyons

LLM Says: "Government secrecy 🤐"

Those national security threat claims? 'No evidence,' VP tells The Reg Exclusive  Despite the Feds' determination to ban Kaspersky's security software in the US, the Russian business continues to push its proposal to open up its data and products to independent third-party review – and prove to Uncle Sam that its code hasn't been and won't be compromised by Kremlin spies.…

...more

FYI: Data from deleted GitHub repos may not actually be deleted

Published: 2024-07-25 19:51:32

Popularity: 15

Author: Thomas Claburn

LLM Says: ""Still accessible""

And the forking Microsoft-owned code warehouse doesn't see this as much of a problem Researchers at Truffle Security have found, or arguably rediscovered, that data from deleted GitHub repositories (public or private) and from deleted copies (forks) of repositories isn't necessarily deleted.…

...more

Post-CrowdStrike, Microsoft to discourage use of kernel drivers by security tools

Published: 2024-07-29 06:30:14

Popularity: 26

Author: Simon Sharwood

LLM Says: ""Driver's Seat""

Now there's an idea – parsing config data in user mode Updated  Microsoft has vowed to reduce cybersecurity vendors' reliance on kernel-mode code, which was at the heart of the CrowdStrike super-snafu this month.…

...more

This uni thought it would be a good idea to do a phishing test with a fake Ebola scare

Published: 2024-08-22 10:32:13

Popularity: 22

Author: Thomas Claburn

LLM Says: "Ebola Alert"

Needless to say, it backfired in a big way University of California Santa Cruz (UCSC) students may be relieved to hear that an emailed warning about a staff member infected with the Ebola virus was just a phishing exercise.…

...more

Using 1Password on Mac? Patch up if you don’t want your Vaults raided

Published: 2024-08-08 13:45:09

Popularity: 43

Author: Connor Jones

LLM Says: "Vaults getting hacked"

Hundreds of thousands of users potentially vulnerable Password manager 1Password is warning that all Mac users running versions before 8.10.36 are vulnerable to a bug that allows attackers to steal vault items.…

...more

US indicts duo over alleged Swatting spree that targeted elected officials

Published: 2024-08-29 22:28:14

Popularity: 12

Author: Iain Thomson

LLM Says: "SWAT TEAM INVADES"

Apparently made over 100 fake crime reports and bomb threats The US government has indicted two men for allegedly reporting almost 120 fake emergencies or crimes in the hope of provoking action by armed law enforcement agencies.…

...more

Intel's Software Guard Extensions broken? Don't panic

Published: 2024-08-27 19:59:33

Popularity: 14

Author: Iain Thomson

LLM Says: "Bug alert!"

More of a storm in a teacup Today's news that Intel's Software Guard Extensions (SGX) security system is open to abuse may be overstated.…

...more

Proof-of-concept code released for zero-click critical IPv6 Windows hole

Published: 2024-08-28 21:20:12

Popularity: 19

Author: Iain Thomson

LLM Says: ""Critical Hole""

If you haven't deployed August's patches, get busy before others do Windows users who haven't yet installed the latest fixes to their operating systems will need to get a move on, as code now exists to exploit a critical Microsoft vulnerability announced by Redmond two weeks ago.…

...more

CrowdStrike's meltdown didn't dent its market dominance … yet

Published: 2024-08-29 02:27:08

Popularity: 12

Author: Jessica Lyons

LLM Says: "Server not found"

Total revenue for Q2 grew 32 percent CrowdStrike's major meltdown a month ago doesn't look like affecting the cyber security vendor's market dominance anytime soon, based on its earnings reported Wednesday.…

...more

Rock Chrome hard enough and get paid half a million

Published: 2024-08-29 16:30:12

Popularity: 7

Author: Thomas Claburn

LLM Says: "💸💥🔨💰"

Google revises Chrome Vulnerability Rewards Program with higher payouts for bug hunters Google's Chrome Vulnerability Rewards Program (VRP) is now significantly more rewarding – with a top payout that's at least twice as substantial.…

...more

UK trio pleads guilty to running $10M MFA bypass biz

Published: 2024-09-03 21:30:07

Popularity: 19

Author: Brandon Vigliarolo

LLM Says: ""Phishing for cash""

Crew bragged they could help crooks raid victims' bank accounts Updated  A trio of men have pleaded guilty to running a multifactor authentication (MFA) bypass ring in the UK, which authorities estimate has raked in millions in less than two years. …

...more

White House thinks it's time to fix the insecure glue of the internet: Yup, BGP

Published: 2024-09-03 22:34:09

Popularity: 12

Author: Thomas Claburn

LLM Says: "Routed fail GIF"

Better late than never The White House on Tuesday indicated it hopes to shore up the weak security of internet routing, specifically the Border Gateway Protocol (BGP).…

...more

Telegram apologizes to South Korea and takes down smutty deepfakes

Published: 2024-09-04 04:28:14

Popularity: 10

Author: Simon Sharwood

LLM Says: "NSFW fail"

Unclear if this is a sign controversial service is cleaning up its act everywhere Controversial social network Telegram has co-operated with South Korean authorities and taken down 25 videos depicting sex crimes.…

...more

Security biz Verkada to pay $3M penalty under deal that also enforces infosec upgrade

Published: 2024-09-05 04:28:07

Popularity: 10

Author: Iain Thomson

LLM Says: "Fine print alert"

Allowed access to 150K cameras, some in sensitive spots, but has been done for spamming Physical security biz Verkada has agreed to cough up $2.95 million following an investigation by the US Federal Trade Commission (FTC) – but the payment won’t make good its past security failings, including a blunder that led to CCTV footage being snooped on by miscreants. Instead, the fine is about spam.…

...more

Security boom is over, with over a third of CISOs reporting flat or falling budgets

Published: 2024-09-05 14:34:10

Popularity: 12

Author: Iain Thomson

LLM Says: "Security Bust"

Good news? Security is still getting a growing part of IT budget It looks like security budgets are coming up against belt-tightening policies, with chief security officers reporting budgets rising more slowly than ever and over a third saying their spending this year will be flat or even reduced.…

...more

To patch this server, we need to get someone drunk

Published: 2024-09-06 07:28:05

Popularity: 13

Author: Simon Sharwood

LLM Says: ""Drunk coding""

When maintenance windows are hard to open, a little lubrication helps On Call  The Register understands consuming alcohol is quite a popular way to wind down from the working week, but each Friday we get the party started early with a new and sober instalment of On Call, the reader contributed column in which you share stories about the emotional hangovers you've earned delivering tech support.…

...more

end