The Register
North Korea's fake IT worker scam hauled in at least $88 million over six years
North Korea's fake IT worker scams netted the hermit kingdom $88 million over six years, according to the US Department of Justice, which thinks it's found the people who run them.…
Apache issues patches for critical Struts 2 RCE bug
We now know the remote code execution vulnerability in Apache Struts 2 disclosed back in November carries a near-maximum severity rating following the publication of the CVE.…
Lights out for 18 more DDoS booters in pre-Christmas Operation PowerOFF push
The Europol-coordinated Operation PowerOFF struck again this week as cross-border cops pulled the plug on 27 more domains tied to distributed denial of service (DDoS) criminality.…
British Army zaps drones out of the sky with laser trucks
The British Army has successfully destroyed flying drones for the first time using a high-energy laser mounted on an armored vehicle. If perfected, the technology could form an effective counter-measure against drone attacks.…
Firefox ditches Do Not Track because nobody was listening anyway
When Firefox 135 is released in February, it'll ship with one less feature: Mozilla plans to remove the Do Not Track toggle from its Privacy and Security settings. …
Citrix goes shopping in Europe and returns with gifts for security-conscious customers
Citrix has gone on a European shopping trip, and come home with its bag of gifts bulging thanks to a pair of major buys: infosec outfits deviceTRUST and Strong Network.…
Blocking Chinese spies from intercepting calls? There ought to be a law
US telecoms carriers would be required to implement minimum cyber security standards and ensure their systems are not susceptible to hacks by nation-state attackers – like Salt Typhoon – under legislation proposed by senator Ron Wyden (D-OR).…
Krispy Kreme Doughnut Corporation admits to hole in security
Doughnut slinger Krispy Kreme has admitted to an attack that has left many customers unable to order online.…
Three more vulns spotted in Ivanti CSA, all critical, one 10/10
Ivanti just put out a security advisory warning of three critical vulnerabilities in its Cloud Services Application (CSA), including a perfect 10.…
US names Chinese national it alleges was behind 2020 attack on Sophos firewalls
The US Departments of Treasury and Justice have named a Chinese business and one of its employees as the actors behind the 2020 exploit of a zero-day flaw in Sophos firewalls…
Microsoft holds last Patch Tuesday of the year with 72 gifts for admins
Microsoft hasn't added too much coal to the stocking this Patch Tuesday, with just 72 fixes, only one of which scored more than nine on the CVSS threat ranking scale.…
US military grounds entire Osprey tiltrotor fleet over safety concerns
The US Navy, Air Force, and Marine Corps have grounded their fleet of Boeing-Bell-made Osprey V-22s on safety grounds.…
AMD secure VM tech undone by DRAM meddling
Researchers have found that the security mechanism AMD uses to protect virtual machine memory can be bypassed with $10 of hardware – and perhaps not even that.…
Fully patched Cleo products under renewed 'zero-day-ish' mass attack
Researchers at security shop Huntress are seeing mass exploitation of a vulnerability affecting three Cleo file management products, even on patched systems.…
Heart surgery device maker's security bypassed, data encrypted and stolen
A manufacturer of devices used in heart surgeries says it's dealing with "a cybersecurity incident" that bears all the hallmarks of a ransomware attack.…
Bitfinex heist gets the Netflix treatment after 'cringey couple' sentenced
A documentary examining the 2016 Bitfinex burglars hits Netflix, bringing the curious case to living rooms for the first time.…
WhatsApp finally fixes View Once flaw that allowed theft of supposedly vanishing pics
WhatsApp has fixed a problem with its View Once feature, designed to protect people's privacy with automatically disappearing pictures and videos.…
Police arrest suspect in murder of UnitedHealthcare CEO, with grainy pics the only tech involved
Police in Pennsylvania have arrested a man suspected of shooting dead the CEO of insurer UnitedHealthcare in New York City, thanks to a McDonald's employee who recognized the suspect in a burger joint – and largely without help from technology.…
China's Salt Typhoon recorded top American officials' calls, says White House
Chinese cyberspies recorded "very senior" US political figures' calls, according to White House security boss Anne Neuberger.…
Crooks stole AWS credentials from misconfigured sites then kept them in open S3 bucket
Exclusive A massive online heist targeting AWS customers during which digital crooks abused misconfigurations in public websites and stole source code, thousands of credentials, and other secrets remains "ongoing to this day," according to security researchers.…