News

EncroChat hack case: RAM, bam... what? Data in transit is data at rest, rules UK Court of Appeal

The Register - Mon, 08/02/2021 - 16:34
That's the Snoopers' Charter in action for you

British prosecutors can make use of evidence gathered by the French and Dutch police from encrypted messaging service Encrochat’s servers thanks to a legal interpretation of whether RAM counts as data storage, the Court of Appeal has ruled.…

Categories: News

Hacked by SolarWinds backdoor masterminds, Mimecast now lays off staff after profit surge

The Register - Sun, 07/02/2021 - 10:04
Plus: British Mensa in data leak blunder, DARPA are Star Wars fans, Sonicwall patch out, and more

In brief  Email security biz Mimecast not only fell victim to the SolarWinds hackers, leading to its own customers being attacked, it is also trimming its workforce amid healthy profits.…

Categories: News

SitePoint hacked: Hashed, salted passwords pinched from web dev learning site via GitHub tool pwnage

The Register - Fri, 05/02/2021 - 19:05
If you started off there, best change your reused credentials

SitePoint, an Australian learn-to-code publishing website, has been compromised while promoting the book Hacking for Dummies on its homepage.…

Categories: News

New VS Code release hits stable channel for everyone who's not on Apple Silicon after last-minute bug found

The Register - Fri, 05/02/2021 - 16:03
Electron 11, source control tweaks, plus general spit and polish

Microsoft has pushed out another update to dev favourite Visual Studio Code, but opted to hold off on the Apple Silicon version after a last-minute bug reared its head.…

Categories: News

That Chrome zero-day bug affects Edge, Vivaldi, and other Chromium-tinged browsers

The Register - Fri, 05/02/2021 - 15:07
Install your updates pronto, folks – it's an active exploit

If you use Google Chrome or a Chromium-based browser such as Microsoft Edge, update it immediately and/or check it for updates over the coming days – there is a zero-day exploit being actively exploited in the older version of Chrome that will also affect other vendors' browsers.…

Categories: News

The Linux box that runs the exec carpark gate is down! A chance for PostgreSQL Man to show his quality

The Register - Fri, 05/02/2021 - 07:55
They still laid him off, though

On Call  This week's episode of On Call, as ever, comes with a warning: Be careful moving that beige box, for you may not realise what it does.…

Categories: News

Cisco reveals critical bug in small biz VPN routers when half the world is stuck working at home

The Register - Fri, 05/02/2021 - 07:05
And we all know how good small business are at patching... NOT

Cisco has addressed a clutch of critical vulnerabilities in its small business and VPN routers that can be exploited by an unauthenticated, remote attacker to execute arbitrary code as the root user. All the attacker needs to do is send a maliciously crafted HTTP request to the web-based management interface.…

Categories: News

Vote machine biz Smartmatic sues Fox News and Trump chums for $2.7bn over bogus claims of rigged 2020 election

The Register - Fri, 05/02/2021 - 02:41
Turns out words have consequences

Electronic voting machine maker Smartmatic has sued Fox News, three of its hosts, and two of Donald Trump’s loyalists – Rudy Giuliani and Sidney Powell – for an eye-popping $2.7bn in defamation damages over the false claims it stole the 2020 presidential election for Joe Biden.…

Categories: News

How do you fix a problem like open-source security? Google has an idea tho constraints may not go down well

The Register - Thu, 04/02/2021 - 19:32
'Try telling leaders of libpng, libjpeg-turbo, openssl, ffmpeg etc they can't make "unilateral" changes to their own projects'

Google has proposed a framework for discussing and addressing open-source security based on factors like verified identity, code review, and trusted builds, but its approach may be at odds with open-source culture.…

Categories: News

Is there a widening gulf between you and your remote workers? Yes – and it’s security shaped

The Register - Thu, 04/02/2021 - 07:30
Tune in online this month and learn how to mind the security gap

Webcast  It’s been almost a year since large parts of the workforce beat a hasty retreat from their offices, and began a mass experiment in working from home, often courtesy of Microsoft 365.…

Categories: News

Nespresso smart cards hacked to provide infinite coffee after someone wasn't too perky about security

The Register - Thu, 04/02/2021 - 06:40
Older commercial machines rely on insecure Mifare Classic payments

Some commercial Nespresso machines in Europe that incorporate a smart card payment system can be manipulated to add unlimited funds to purchase coffee, thanks to reliance on technology that's been known to be insecure for more than a decade.…

Categories: News

Myanmar’s new military government bans Facebook

The Register - Thu, 04/02/2021 - 00:24
Oh look, Cloudflare spots a sudden surge in use of other messaging apps

The new self-appointed military government of Myanmar has temporarily banned Facebook.…

Categories: News

More patches for SolarWinds Orion after researchers find flaw allowing low-priv users to execute code, among others

The Register - Wed, 03/02/2021 - 21:25
Probably not used by last year's US government-busting attackers, though

As if that supply chain attack wasn't bad enough, SolarWinds has had to patch its Orion software again after eagle-eyed researchers discovered fresh vulnerabilities – including one that can be exploited to achieve remote code execution.…

Categories: News

Tiny Kobalos malware seen backdooring SSH tools, menacing supercomputers, an ISP, and more – ESET

The Register - Wed, 03/02/2021 - 12:30
Linux variant studied, dissected in detail in case you want to look out for it

ESET researchers say they have found a lightweight strain of malware that targets multiple OSes and has hit supercomputers, an ISP, and other organisations.…

Categories: News

Location tracking report: X-Mode SDK still in wide use in Android apps despite Google ban

The Register - Wed, 03/02/2021 - 10:15
450 Android apps track location, 1.7bn downloads, 44% use X-Mode code: only 10% pulled off Play Store

A report on Android apps that do location tracking identified 450 apps that use tracker SDKs, many of which use an SDK called X-Mode, which Apple and Google have banned, but are still in Google's Play Store.…

Categories: News

Rubbish software security patches responsible for a quarter of zero-days last year

The Register - Wed, 03/02/2021 - 08:03
Google wants researchers, vendors to stop making attacks easy

Enigma  To limit the impact of zero-day vulnerabilities, Google security researcher Maddie Stone would like those developing software fixes to stop delivering shoddy patches.…

Categories: News

Spanish banished: Google Chrome to snub Camerfirma for lax cert management

The Register - Tue, 02/02/2021 - 08:02
Mozilla meanwhile wants to continue compliance discussions with security certificate vendor

When Google Chrome 90 arrives in April, visitors to websites that depend on TLS server authentication certificates from AC Camerfirma SA, a digital certificate authority based in Madrid, Spain, will find that those sites no longer present the secure lock icon.…

Categories: News

In wake of Apple privacy controls, Facebook mulls just begging its iOS app users to let it track them over the web

The Register - Mon, 01/02/2021 - 23:42
I am once again asking for your financial support, says Zuckerberg's empire

Facebook has created a new screen in its iOS app that will urge people to allow it to continue stalking their online activities for targeted advertising.…

Categories: News

US court system ditches electronic filing, goes paper-only for sensitive documents following SolarWinds hack

The Register - Mon, 01/02/2021 - 21:25
Lawyers required to hand in dead-tree copies. No, seriously

The US court system has banned the electronic submission of legal documents in sensitive cases out of concern that Russian hackers have compromised the filing system.…

Categories: News

Chrome 89 beta: Google presses on with 'advanced hardware interactions' that Mozilla, Apple see as harmful

The Register - Mon, 01/02/2021 - 17:54
Adding Serial API, Web NFC support, richer human interface device support

Google has released a beta of Chrome 89, adding further hardware interaction APIs even though Mozilla and Apple consider many of these features harmful, as well as introducing a desktop-sharing API for Windows and Chrome OS.…

Categories: News

Pages

Subscribe to Sec Tec Limited aggregator - News