News
Microsoft waited 6 months to patch actively exploited admin-to-kernel vulnerability
Infosec in brief Cybersecurity researchers informed Microsoft that Notorious North Korean hackers Lazarus Group discovered the "holy grail" of rootkit vulnerabilities in Windows last year, but Redmond still took six months to patch the problem.…
Cybercrime crew Magnet Goblin bursts onto the scene exploiting Ivanti holes
There's yet another group of miscreants out there hijacking insecure Ivanti devices: A new, financially motivated gang dubbed Magnet Goblin has emerged from the shadowy digital depths with a knack for rapidly exploiting newly disclosed vulnerabilities before vendors have issued a fix.…
Microsoft confirms Russian spies stole source code, accessed internal systems
Microsoft has now confirmed that the Russian cyberspies who broke into its executives' email accounts stole source code and gained access to internal systems. The Redmond giant has characterized the intrusion as "ongoing."…
Change Healthcare registers pulse after crippling ransomware attack
Change Healthcare has taken the first steps toward a full recovery from the ransomware attack in February by bringing its electronic prescription services back online.…
Swiss cheese security? Play ransomware gang milks government of 65,000 files
The Swiss government had around 65,000 files related to it stolen by the Play ransomware gang during an attack on an IT supplier, its National Cyber Security Center (NCSC) says.…
Font security 'still a Helvetica of a problem' says Australian graphics outfit Canva
Online graphic design platform Canva went looking for security problems in fonts, and found three – in "strange places."…
Securing open source software: Whose job is it, anyway?
The US government and some of the largest open source foundations and package repositories have announced a series of initiatives intended to improve software supply-chain security, while also repeating calls for developers to increase support for such efforts.…
We're not Meta support: State AGs tell Zuck to fix rampant account takeover problem
A group of 41 US state attorneys general, tired of serving as a customer complaint clearinghouse for Facebook and Instagram users, have sent a letter to Meta asking it to figure out how to reduce a "dramatic and persistent spike" in account takeovers.…
Chrome users – get an alert when extensions are in danger of falling into wrong hands
Millions of Chrome users now have a way to guard against the threat of extension subversion, that is, if they don't mind installing yet another browser extension.…
Possible China link to Change Healthcare ransomware attack
A criminal claiming to be an ALPHV/BlackCat affiliate — the gang responsible for the widely disruptive Change Healthcare ransomware infection last month — may have ties to Chinese government-backed cybercrime syndicates.…
JetBrains TeamCity under attack by ransomware thugs after disclosure mess
Security researchers are increasingly seeing active exploit attempts using the latest vulnerabilities in JetBrains' TeamCity that in some cases are leading to ransomware deployment.…
Belgian ale legend Duvel’s brewery borked as ransomware halts production
Belgian beer brewer Duvel says a ransomware attack has brought its facility to a standstill while its IT team works to remediate the damage.…
VMware urges emergency action to blunt hypervisor flaws
Hypervisors are supposed to provide an inviolable isolation layer between virtual machines and hardware. But hypervisor heavyweight VMware by Broadcom yesterday revealed its hypervisors are not quite so inviolable as it might like.…
Here’s something else AI can do: expose bad infosec to give cyber-crims a toehold in your organization
Stolen ChatGPT credentials are a hot commodity on the dark web, according to Singapore-based threat intelligence firm Group-IB, which claims to have found some 225,000 stealer logs containing login details for the service last year.…
US lawmakers want ByteDance to divest TikTok or face a ban
A group of US lawmakers introduced legislation on Tuesday that, if passed, would force Chinese internet concern ByteDance to divest TikTok – its most valuable property – or see it banned in the US.…
Lawsuit claims gift card fraud is the gift that keeps on giving, to Google
Google has been accused of profiting from gift card scams.…
Chinese chap charged with stealing Google’s AI datacenter secrets
A now-former Google employee has been charged with stealing the ad giant’s AI trade secrets while quietly working for two Chinese companies – after easily defeating whatever security controls Big G had in place.…
FBI: Critical infrastructure suffers spike in ransomware attacks
Digital crimes potentially cost victims more than $12.5 billion last year, according to the FBI's latest Internet Crime Complaint Center (IC3) annual report. …
Apple's trademark tight lips extend to new iPhone, iPad zero-days
Apple's latest security patches address four vulnerabilities affecting iOS and iPadOS, including two zero-days that intel suggests attackers have already exploited.…
Capita says 2023 cyberattack costs a factor as it reports staggering £100M+ loss
Outsourcing giant Capita today reported a net loss of £106.6 million ($135.6 million) for calendar 2023, with the costly cyberattack by criminals making a hefty dent in its annual financials.…