The Register
Coding error in forgotten API blamed for massive data breach
The data breach at Australian telco Optus, which saw over nine million customers' personal information exposed, has been blamed on a coding error that broke API access controls, and was left in place for years.…
Crooks get their hands on 500K+ radiology patients' records in cyber-attack
Consulting Radiologists has notified almost 512,000 patients that digital intruders accessed their personal and medical information during a February cyberattack.…
Biden puts a bullet in Kaspersky: Sales, updates to be banned in America
Breaking news The Biden administration has banned the sale of Kaspersky software in the United States, arguing the Russian biz is a national security risk.…
Car dealer software bigshot CDK pulls systems offline twice amid 'cyber incident'
The vendor behind the software on which nearly 15,000 car dealerships across the US rely says an ongoing "cyber incident" has forced it to pull systems offline for a second time in as many days.…
Crypto exchange Kraken accuses blockchain security outfit CertiK of extortion
Kraken, one of the largest cryptocurrency exchanges in the world, has accused a trio of security researchers of discovering a critical bug, expoliting it to steal millions in digital cash, then using stolen funds to extort the exchange for more.…
Russia's cyber spies still threatening French national security, democracy
A fresh report into the Nobelium offensive cyber crew published by France's computer emergency response team (CERT-FR) highlights the group's latest tricks as the country prepares for a major election and to host this year's Olympic and Paralympic Games.…
Qilin: We knew our Synnovis attack would cause a healthcare crisis at London hospitals
Interview The ransomware gang responsible for the current healthcare crisis at London hospitals says it has no regrets about the attack, which was entirely deliberate, it told The Register in an interview.…
Amtrak confirms crooks are breaking into user accounts, derailing email addresses
US rail company Amtrak is writing to users of its Guest Rewards program to inform them that their data is potentially at risk following a derailment of their account security. …
That PowerShell 'fix' for your root cert 'problem' is a malware loader in disguise
Crafty criminals are targeting thousands of orgs around the world in social-engineering attacks that use phony error messages to trick users into running malicious PowerShell scripts. …
Rogue uni IT director pleads guilty after fraudulently buying $2.1M of tech
A now-former IT director has pleaded guilty to defrauding the university at which he was employed – and a computer equipment supplier – for $2.1 million over five years.…
Dark-web kingpin puts 'stolen' internal AMD databases, source code up for sale
AMD's IT team is no doubt going through its logs today after cyber-crooks put up for sale what is claimed to be internal data stolen from the US microprocessor designer.…
EU attempt to sneak through new encryption-eroding law slammed by Signal, politicians
On Thursday, the EU Council is scheduled to vote on a legislative proposal that would attempt to protect children online by disallowing confidential communication.…
CHERI Alliance formed to promote memory security tech ... but where's Arm?
A group of technology organizations has formed the CHERI Alliance CIC (Community Interest Company) to promote industry adoption of the security technology focused on memory access.…
Uncle Sam ends financial support to orgs hurt by Change Healthcare attack
The US government is winding down its financial support for healthcare providers originally introduced following the ransomware attack at Change Healthcare in February.…
NHS boss says Scottish trust didn't meet attackers' demands
The chief exec at NHS Dumfries and Galloway will write to thousands of folks in the Scottish region whose data was stolen by criminals, admitting the lot of it was published after the trust did not give in to the miscreants' demands.…
VMware by Broadcom warns of two critical vCenter flaws, plus a nasty sudo bug
VMware by Broadcom has revealed a pair of critical-rated flaws in vCenter Server – the tool used to manage virtual machines and hosts in its flagship Cloud Foundation and vSphere suites.…
Arm security defense shattered by speculative execution 95% of the time
In 2018, chip designer Arm introduced a hardware security feature called Memory Tagging Extensions (MTE) as a defense against memory safety bugs. But it may not be as effective as first hoped.…
Shoddy infosec costs PwC spinoff and NMA $11.3M in settlement with Uncle Sam
Two consulting firms, Guidehouse and Nan McKay and Associates, have agreed to pay a total of $11.3 million to resolve allegations of cybersecurity failings over their roll-out of COVID-19 assistance.…
Suspected underworld Empire Market bosses face possible life behind bars
The two alleged administrators of Empire Market, a dark-web bazaar that peddled drugs, malware, digital fraud, and other illegal stuff, have been detained on charges related to owning and operating the illicit souk.…
Blackbaud has to cough up a few million dollars more over 2020 ransomware attack
Months after escaping without a fine from the US Federal Trade Commission (FTC), the luck of cloud software biz Blackbaud ran out when it came to reaching a settlement with California's attorney general.…