///

Headlines : Theregister Sec News   Page 1    



Ransomware feared as IT 'issues' force Octapharma Plasma to close 150+ .. - 19/04 6:37 am

Source blames BlackSuit infection ??? as separately ISP Frontier confirms cyberattack Octapharma Plasma has blamed IT "network issues" for the ongoing closure of its 150-plus centers across the US. It's feared a ransomware infection may be the root cause of the medical firm's ailment.???





Crooks exploit OpenMetadata holes to mine crypto ??? and leave a sob story .. - 19/04 5:56 am

'I want to buy a car. That's all' Crooks are exploiting month-old OpenMetadata vulnerabilities in Kubernetes environments to mine cryptocurrency using victims' resources, according to Microsoft.???





Prolific phishing-made-easy emporium LabHost knocked offline in cyber-cop .. - 19/04 4:12 am

Police emit Spotify Wrapped-style videos to let crims know they're being hunted Feature ?? Cops have brought down a dark-web souk that provided cyber criminals with convincing copies of trusted brands' websites for use in phishing campaigns.???





Korean researcher details scheme abusing Apple's third-party pickup policy - 19/04 3:48 am

Criminals make lucrative use of stolen credit cards Black Hat Asia ?? Speaking at Black Hat Asia on Thursday, a Korean researcher revealed how the discovery of one phishing website led to uncovering an operation whose activities leveraged second-hand shops and included using Apple???s "someone-else pickup" method to cash in.???





House passes bill banning Uncle Sam from snooping on citizens via data .. - 19/04 1:29 am

Vote met strong opposition from Biden's office A draft law to restrict the US government's ability to procure data on citizens through data brokers will progress to the Senate after being passed in the House of Representatives.???





185K people's sensitive data in the pits after ransomware raid on Cherry .. - 18/04 10:00 pm

Extent of information seized will be a concern for those affected Ransomware strikes at yet another US healthcare organization led to the theft of sensitive data belonging to just shy of 185,000 people.???





EU tells Meta it can't paywall privacy - 18/04 8:19 pm

Platforms should not confront users with 'binary choice' over personal data use The EU's Data Protection Board (EDPB) has told large online platforms they should not offer users a binary choice between paying for a service and consenting to their personal data being used to provide targeted advertising.???





Cisco creates architecture to improve security and sell you new switches - 18/04 3:01 pm

Hypershield detects bad behavior and automagically reconfigures networks to snuff out threats Cisco has developed a product called Hypershield that it thinks represents a new way to do network security.???





Singapore infosec boss warns China/West tech split will be bad for .. - 18/04 1:32 pm

When you decide not to trust a big chunk of the supply chain, tech (and trade) get harder One of the biggest challenges Singapore faces is the potential for a split between tech stacks developed and used by China and the West, according to the island nation's Cyber Security Administration (CSA) chief executive David Koh.???





Taiwanese film studio snaps up Chinese surveillance camera specialist Dahua - 18/04 11:30 am

Stymied by sanctions, it had to go ??? but where? Chinese surveillance camera manufacturer Zhejiang Dahua Technology, which has found itself on the USA???s entity list of banned orgs, has fully sold off its stateside subsidiary for $15 million to Taiwan's Central Motion Picture Corporation, according to the firm's annual report released on Monday.???





Hugely expanded Section 702 surveillance powers set for US Senate vote - 18/04 7:44 am

Opponents warn almost anyone could be asked to share info with Uncle Sam On Thursday the US Senate is expected to reauthorize the contentious warrantless surveillance powers conferred by Section 702 of the Foreign Intelligence Surveillance Act (FISA), and may even strengthen them with language that, according to US Senator Ron Wyden (D-OR), "will force a huge range of companies and individuals to spy for the government."???





Kremlin's Sandworm blamed for cyberattacks on US, European water utilities - 18/04 3:56 am

Water tank overflowed during one system malfunction, says Mandiant The Russian military's notorious Sandworm crew was likely behind cyberattacks on US and European water plants that, in at least one case, caused a tank to overflow.???





Exploit code for Palo Alto Networks zero-day now public - 17/04 9:30 pm

Race on to patch as researchers warn of mass exploitation of directory traversal bug Various infosec researchers have released proof-of-concept (PoC) exploits for the maximum-severity vulnerability in Palo Alto Networks' PAN-OS used in GlobalProtect gateways.???





OpenAI's GPT-4 can exploit real vulnerabilities by reading security .. - 17/04 6:15 pm

While some other LLMs appear to flat-out suck AI agents, which combine large language models with automation software, can successfully exploit real world security vulnerabilities by reading security advisories, academics have claimed.???





Japanese government rejects Yahoo ! infosec improvement plan - 17/04 1:44 pm

Just doesn't believe it will sort out the mess that saw data leak from LINE messaging app Japan's government has considered the proposed security improvements developed by Yahoo ! , found them wanting, and ordered the onetime web giant to take new measures.???





Fire in the Cisco! Networking giant's Duo MFA message logs stolen in phish .. - 17/04 8:40 am

Also warns of brute force attacks targeting its own VPNs, Check Point, Fortinet, SonicW





MGM says FTC can't possibly probe its ransomware downfall ??? watchdog .. - 17/04 4:52 am

What a twist! MGM Resorts wants the FTC to halt a probe into last year's ransomware infection at the mega casino chain ??? because the watchdog's boss Lina Khan was a guest at one of its hotels during the cyberattack, apparently.???





Alleged cryptojacker accused of stealing $3.5M from cloud to mine under .. - 17/04 12:49 am

No prizes for guessing the victims A Nebraska man will appear in court today to face charges related to allegations that he defrauded cloud service providers of more than $3.5 million in a long-running cryptojacking scheme.???





SIM swap crooks solicit T-Mobile US, Verizon staff via text to do their .. - 16/04 11:41 pm

No breach responsible for employee contact info getting out, says T-Mo T-Mobile US employees say they are being sent text messages that offer them cash to perform illegal SIM swaps for supposed criminals.???





Open sourcerers say suspected xz-style attacks continue to target .. - 16/04 10:07 pm

Social engineering patterns spotted across range of popular projects Open source groups are warning the community about a wave of ongoing attacks targeting project maintainers similar to those that led to the recent attempted backdooring of a core Linux library.???





Change Healthcare???s ransomware attack costs edge toward $1B so far - 16/04 9:17 pm

First glimpse at attack financials reveals huge pain UnitedHealth, parent company of ransomware-besieged Change Healthcare, says the total costs of tending to the February cyberattack for the first calendar quarter of 2024 currently stands at $872 million.???





CISA in a flap as Chirp smart door locks can be trivially unlocked remotely - 16/04 6:35 am

Hard-coded credentials last thing you want in home security app Some smart locks controlled by Chirp Systems' software can be remotely unlocked by strangers thanks to a critical security vulnerability.???





US senator wants to put the brakes on Chinese EVs - 16/04 2:08 am

Fears of low-cost invasion and data spies spark call for ban Electric vehicles may become a new front in America's tech war with China after a US senator called for Washington DC to block Chinese-made EVs to protect domestic industries and national security.???





Delinea Secret Server customers should apply latest patches - 16/04 2:04 am

Attackers could nab an org's most sensitive keys if left unaddressed Updated ?? Customers of Delinea's Secret Server are being urged to upgrade their installations "immediately" after a researcher claimed a critical vulnerability could allow attackers to gain admin-level access.???





Roku makes 2FA mandatory for all after nearly 600K accounts pwned - 16/04 1:52 am

Streamer says access came via credential stuffing Streaming giant Roku is making 2FA mandatory after attackers accessed around 591,000 customer accounts earlier this year.???





Identifying third-party risk - 15/04 4:03 pm

The prima facie case for real-time threat intelligence Webinar ?? Cybercriminals are always on the hunt for new ways to breach your privacy, and busy supply chains often look like a good way to get in under the wire.???





US House approves FISA renewal ??? warrantless surveillance and all - 15/04 9:58 am

PLUS: Chinese chipmaker Nexperia attacked; A Microsoft-signed backdoor; CISA starts scanning your malwa





Zero-day exploited right now in Palo Alto Networks' GlobalProtect gateways - 13/04 6:46 am

Out of the PAN-OS and into the firewall, a Python backdoor this way comes Palo Alto Networks on Friday issued a critical alert for an under-attack vulnerability in the PAN-OS software used in its firewall-slash-VPN products.???





Google One VPN axed for everyone but Pixel loyalists ... for now - 13/04 4:21 am

Another one bytes the dust In an incredibly rare move, Google is killing off one of its online services ??? this time, VPN for Google One.???





Microsoft breach allowed Russian spies to steal emails from US government - 12/04 10:37 pm

Affected federal agencies must comb through mails, reset API keys and passwords The US Cybersecurity and Infrastructure Security Agency (CISA) warns that Russian spies who gained access to Microsoft's email system were able to steal sensitive data, including authentication details and that immediate remedial action is required by affected agencies.???





French issue alerte rouge after local governments knocked offline by cyber .. - 12/04 1:30 pm

Embarrassing, as its officials are in the US to discuss Olympics cyber threats Several French municipal governments' services have been knocked offline following a "large-scale cyber attack" on their shared servers.???





Apple stops warning of 'state-sponsored' attacks, now alerts about .. - 12/04 12:46 am

Report claims India's government, which is accused of using Pegasus at home, was displeased Apple has made a significant change to the wording of its threat notifications, opting not to attribute attacks to a specific source or perpetrator, but categorizing them broadly as "mercenary spyware."???





Space Force boss warns 'the US will lose' without help from Musk and Bezos - 12/04 7:30 am

China, Russia have muscled up, and whoever wins up there wins down here The commander of the US Space Force (USSF) has warned that America risks losing its dominant position in space, and therefore on Earth too.???





96% of US hospital websites share visitor info with Meta, Google, data .. - 12/04 12:05 am

Could have been worse ??? last time researchers checked it was 98.6% Hospitals ??? despite being places where people implicitly expect to have their personal details kept private ??? frequently use tracking technologies on their websites to share user information with Google, Meta, data brokers, and other third parties, according to research published today.???





Global taxi software vendor exposes details of nearly 300K across UK and .. - 11/04 5:30 pm

High-profile individuals including MPs said to be caught up in leak Exclusive ?? Taxi software biz iCabbi recently fixed an issue that exposed the personal information of nearly 300,000 individuals via an unprotected database.???





It's 2024 and Intel silicon is still haunted by data-spilling Spectre - 11/04 4:52 am

Go, go InSpectre Gadget Intel CPU cores remain vulnerable to Spectre data-leaking attacks, say academics at VU Amsterdam.???





Rust rustles up fix for 10/10 critical command injection bug on Windows - 10/04 9:15 pm

BatBadBut hits Erlang, Go, Python, Ruby as well Programmers are being urged to update their Rust versions after the security experts working on the language addressed a critical vulnerability that could lead to malicious command injections on Windows machines.???





X fixes URL blunder that could enable convincing social media phishing .. - 10/04 6:45 pm

Poorly implemented rule allowed miscreants to deceive users with trusted URLs Elon Musk's X has apparently fixed an embarrassing issue implemented earlier in the week that royally bungled URLs on the social media platform formerly known as Twitter.???





Turning the tide on third-party risk - 10/04 4:39 pm

Using threat intelligence to mitigate against security breaches Webinar ?? There are some unhappy projections out there about the prevalence of third-party security breaches.???





Chrome Enterprise Premium promises extra security ??? for a fee - 10/04 2:26 pm

Paying for browsers is no longer a memory from the 1990s Cloud Next ?? Hoping to upsell freeloading corporate users of its Chrome browser, Google has announced Chrome Enterprise Premium ??? which comes with a dash of AI security sauce for just $6 per user per month.???




News Buzz     >>



Malaysia's growth accelerates, signalling recovery in .. - Straitstimes
Malaysia's growth accelerates, signalling recovery in 2024 ?? The Straits Times
News Maker     >>



Johor's special zones including with Singapore could .. - CNA
Johor's special zones including with Singapore could help its economy outpace other Malaysian states: PM Anwar ?? CNA
World     >>



Don't involve me in Najib's 'supplementary order' .. - FMT
Don't involve me in Najib's 'supplementary order' issue, says Anwar ?? Free Malaysia Today New twist in Najib's bid to serve jail term at home as two ministers dispute claims over supposed royal order ?? CNA Should Malaysia???s Najib be under house arrest? Jailed ex-PM persists with pursuit of ..
Business     >>



Trump criminal case: Full 12-person jury seated in .. - BBC
Trump criminal case: Full 12-person jury seated in Manhattan ?? BBC.com Hear what Trump said minutes after jury was seated in hush money trial ?? CNN Dismissed 'Juror Number 4' calls judge 'cowardly' over being dismissed ?? The Journal News 12 jurors picked in Trump hush money trial as lawyers ..
Tech     >>



ViewSonic Introduces Next-Gen Monitors: Zoom and .. - Prnewswire
ViewSonic Introduces Next-Gen Monitors: Zoom and Windows Hello Certified Pop-Up Webcam and USB-C Docking ?? PR Newswire
Tech Hack     >>



Hugh Grant has been priced out of his 'phone hacking' .. - Voxpolitical
Hugh Grant has been priced out of his 'phone hacking' lawsuit against The Sun ?? Vox Political
Wireless Mobile     >>



Millions of iPhone and Android owners warned of .. - The-sun
Millions of iPhone and Android owners warned of money-hungry criminals lurking in popular app ??? 4 red f... ?? The US Sun
News Security     >>



Breach Roundup: LabHost Goes Down - .. - Bankinfosecurity
Breach Roundup: LabHost Goes Down ?? BankInfoSecurity.com
Google Future     >>



Google Consolidates AI-Building Teams Into DeepMind - .. - Pymnts
Google Consolidates AI-Building Teams Into DeepMind ?? PYMNTS.com
Automotive Future     >>



University of Surrey launches self-driving cars safety .. - BBC
University of Surrey launches self-driving cars safety project ?? BBC.com