The Register

Subscribe to The Register feed
Biting the hand that feeds IT — Enterprise Technology News and Analysis
Updated: 1 hour 4 min ago

China-linked group abuses Fortinet 0-day with post-exploit VPN-credential stealer

Tue, 19/11/2024 - 23:02
No word on when or if the issue will be fixed

Chinese government-linked snoops are exploiting a zero-day bug in Fortinet's Windows VPN client to steal credentials and other information, according to memory forensics outfit Volexity.…

Categories: News

Russian suspected Phobos ransomware admin extradited to US over $16M extortion

Tue, 19/11/2024 - 21:55
This malware is FREE for EVERY crook ($300 decryption keys sold separately)

A Russian citizen has been extradited from South Korea to the United States to face charges related to his alleged role in the Phobos ransomware operation.…

Categories: News

America's drinking water systems have a hard-to-swallow cybersecurity problem

Tue, 19/11/2024 - 19:59
More than 100 million rely on systems rife with vulnerabilities, says EPA OIG

Nearly a third of US residents are served by drinking water systems with cybersecurity shortcomings, the Environmental Protection Agency's Office of Inspector General found in a recent study – and the agency lacks its own system to track potential attacks. …

Categories: News

Palo Alto Networks tackles firewall-busting zero-days with critical patches

Tue, 19/11/2024 - 15:29
Amazing that these two bugs got into a production appliance, say researchers

Palo Alto Networks (PAN) finally released a CVE identifier and patch for the zero-day exploit that caused such a fuss last week.…

Categories: News

Navigating third-party risks

Tue, 19/11/2024 - 14:33
Strategies for mitigating external access vulnerabilities and safeguarding sensitive data

Webinar  As organizations increasingly rely on third-party contractors, vendors, and service providers, the security risks associated with third-party access can become a top priority.…

Categories: News

Crook breaks into AI biz, points $250K wire payment at their own account

Tue, 19/11/2024 - 12:31
Fastidious attacker then tidied up email trail behind them

A Maryland AI company has confirmed to the Securities and Exchange Commission (SEC) that it lost $250,000 to a misdirected wire payment.…

Categories: News

Join in the festive cybersecurity fun

Tue, 19/11/2024 - 09:10
Get hands-on cybersecurity training this seasonal challenge

Sponsored Post  Are you ready to pit your wits against the cyber exercises featured in the Holiday Hack Challenge 2024: Snow-maggedon?…

Categories: News

iOS 18 added secret and smart security feature that reboots iThings after three days

Tue, 19/11/2024 - 08:31
Security researcher's reverse engineering effort reveals undocumented reboot timer that will make life harder for attackers

Apple's latest mobile operating system, iOS 18, appears to have added an undocumented security feature that reboots devices if they’re not used for 72 hours.…

Categories: News

Ford 'actively investigating' after employee data allegedly parked on leak site

Mon, 18/11/2024 - 23:58
Plus: Maxar Space Systems confirms employee info stolen in digital intrusion

Ford Motor Company says it is looking into allegations of a data breach after attackers claimed to have stolen an internal database containing 44,000 customer records and dumped the info on a cyber crime souk for anyone to "enjoy."…

Categories: News

Critical 9.8-rated VMware vCenter RCE bug exploited after patch fumble

Mon, 18/11/2024 - 22:29
If you didn't fix this a month ago, your to-do list probably needs a reshuffle

Two VMware vCenter server bugs, including a critical heap-overflow vulnerability that leads to remote code execution (RCE), have been exploited in attacks after Broadcom’s first attempt to fix the flaws fell short.…

Categories: News

T-Mobile US 'monitoring' China's 'industry-wide attack' amid fresh security breach fears

Mon, 18/11/2024 - 20:43
Un-carrier said to be among those hit by Salt Typhoon, including AT&T, Verizon

T-Mobile US said it is "monitoring" an "industry-wide" cyber-espionage campaign against American networks – amid fears Chinese government-backed spies compromised the un-carrier among with various other telecommunications providers.…

Categories: News

Sweden's 'Doomsday Prep for Dummies' guide hits mailboxes today

Mon, 18/11/2024 - 16:03
First in six years is nearly three times the size of the older, pre-NATO version

Residents of Sweden are to receive a handy new guide this week that details how to prepare for various types of crisis situations or wartime should geopolitical events threaten the country.…

Categories: News

Deepen your knowledge of Linux security

Mon, 18/11/2024 - 14:42

Event  The security landscape is constantly shifting. If you're running Linux, staying ahead may rely on understanding the challenges - and opportunities - unique to Linux environments.…

Categories: News

Teen serial swatter-for-hire busted, pleads guilty, could face 20 years

Mon, 18/11/2024 - 00:31
PLUS: Cost of Halliburton hack disclosed; Time to dump old D-Link NAS; More UN cybercrime convention concerns; and more

Infosec in brief  A teenager has pleaded guilty to calling in more than 375 fake threats to law enforcement, and now faces years in prison.…

Categories: News

Will passkeys ever replace passwords? Can they?

Sun, 17/11/2024 - 18:30
Here's why they really should

Systems Approach  I have been playing around with passkeys, or as they are formally known, discoverable credentials.…

Categories: News

Rust haters, unite! Fil-C aims to Make C Great Again

Sat, 16/11/2024 - 10:12
It's memory-safe, with a few caveats

Developers looking to continue working in the C and C++ programming languages amid the global push to promote memory-safe programming now have another option that doesn't involve learning Rust.…

Categories: News

Swiss cheesed off as postal service used to spread malware

Sat, 16/11/2024 - 07:07
QR codes arrive via an age-old delivery system

Switzerland's National Cyber Security Centre (NCSC) has issued an alert about malware being spread via the country's postal service.…

Categories: News

Bloke behind Helix Bitcoin launderette jailed for three years, hands over $400M

Sat, 16/11/2024 - 00:58
Digital money laundering pays, until it doesn't

An Ohio man, who operated the Grams dark-web search engine and the Helix cryptocurrency money-laundering service associated with it, has been sentenced to three years in prison.…

Categories: News

Letting chatbots run robots ends as badly as you'd expect

Sat, 16/11/2024 - 00:03
LLM-controlled droids easily jailbroken to perform mayhem, researchers warn

Science fiction author Isaac Asimov proposed three laws of robotics, and you'd never know it from the behavior of today's robots or those making them.…

Categories: News

Mystery Palo Alto Networks hijack-my-firewall zero-day now officially under exploit

Fri, 15/11/2024 - 21:07
Yank access to management interface, stat

A critical zero-day vulnerability in Palo Alto Networks' firewall management interface that can allow an unauthenticated attacker to remotely execute code is now officially under active exploitation.…

Categories: News

Pages