The Register
Ghost ransomware crew continues to haunt IT depts with scarily bad infosec
The operators of Ghost ransomware continue to claim victims and score payments, but keeping the crooks at bay is possible by patching known vulnerabilities and some basic infosec actions, according to a joint advisory issued Wednesday by the FBI and US Cybersecurity and Infrastructure Security Agency.…
Medusa ransomware gang demands $2M from UK private health services provider
Exclusive HCRG Care Group, a private health and social services provider, has seemingly fallen victim to the Medusa ransomware gang, which is threatening to leak what's claimed to be stolen internal records unless a substantial ransom is paid.…
US Army soldier linked to Snowflake extortion rampage admits breaking the law
A US Army soldier suspected of hacking AT&T and Verizon has admitted leaking online people's private call records.…
Trump’s DoD CISO pick previously faced security clearance suspension
Donald Trump's nominee for a critical DoD cybersecurity role sports a resume that outshines many of his past picks, despite previously suspended security clearance.…
Check out this free automated tool that hunts for exposed AWS secrets in public repos
A free automated tool that lets anyone scan public GitHub repositories for exposed AWS credentials has been released.…
Hundreds of Dutch medical records bought for pocket change at flea market
Typically shoppers can expect to find tie-dye t-shirts, broken lamps and old disco records at flea markets, now it seems storage drives filled with huge volumes of sensitive data can be added to that list.…
London celebrity talent agency reports itself to ICO following Rhysida attack claims
A London talent agency has reported itself to the UK's data protection watchdog after the Rhysida ransomware crew last week claimed it had attacked the business, which represents luminaries of stage and screen.…
Healthcare outfit that served military personnel settles allegations it faked infosec compliance for $11 million
An alleged security SNAFU that occurred during the Obama administration has finally been settled under the second Trump administration.…
Palo Alto firewalls under attack as miscreants chain flaws for root access
A flaw patched last week by Palo Alto Networks is now under active attack and, when chained with two older vulnerabilities, allows attackers to gain root access to affected systems.…
Snake Keylogger slithers into Windows, evades detection with AutoIt-compiled payload
A new variant of Snake Keylogger is making the rounds, primarily hitting Windows users across Asia and Europe. This strain also uses the BASIC-like scripting language AutoIt to deploy itself, adding an extra layer of obfuscation to help it slip past detection.…
US newspaper publisher uses linguistic gymnastics to avoid saying its outage was due to ransomware
US newspaper publisher Lee Enterprises is blaming its recent service disruptions on a "cybersecurity attack," per a regulatory filing, and is the latest company to avoid using the dreaded R word.…
FreSSH bugs undiscovered for years threaten OpenSSH security
Researchers can disclose two brand-new vulnerabilities in OpenSSH now that patches have been released.…
Time to make C the COBOL of this century
Opinion Nobody likes The Man. When a traffic cop tells you to straighten up and slow down or else, profound thanks are rarely the first words on your lips. Then you drive past a car embedded in a tree, surrounded by blue lights and cutting equipment. Perhaps Officer Dibble had a point.…
Indian authorities seize loot from collapsed BitConnect crypto scam
Indian authorities seize loot from BitConnect crypto-Ponzi scheme Devices containing crypto wallets tracked online, then in the real world India’s Directorate of Enforcement has found and seized over $200 million of loot it says are the proceeds of the BitConnect crypto-fraud scheme.…
XCSSET macOS malware returns with first new version since 2022
Microsoft says there's a new variant of XCSSET on the prowl for Mac users – the first new iteration of the malware since 2022.…
Twin Google flaws allowed researcher to get from YouTube ID to Gmail address in a few easy steps
Infosec In Brief A security researcher has found that Google could leak the email addresses of YouTube channels, which wasn’t good because the search and ads giant promised not to do that.…
Fujitsu worries US tariffs will see its clients slow digital spend
Asia In Brief The head of Fujitsu’s North American operations has warned that the Trump administration’s tariff plans will be bad for business.…
This open text-to-speech model needs just seconds of audio to clone your voice
Hands on Palo Alto-based AI startup Zyphra unveiled a pair of open text-to-speech (TTS) models this week said to be capable of cloning your voice with as little as five seconds of sample audio. In our testing, we generated realistic results with less than half a minute of recorded speech.…
Nearly 10 years after Data and Goliath, Bruce Schneier says: Privacy’s still screwed
Interview It has been nearly a decade since famed cryptographer and privacy expert Bruce Schneier released the book Data and Goliath: The Hidden Battles to Collect Your Data and Control Your World - an examination of how government agencies and tech giants exploit personal data. Today, his predictions feel eerily accurate.…
If you dread a Microsoft Teams invite, just wait until it turns out to be a Russian phish
Digital thieves – quite possibly Kremlin-linked baddies – have been emailing out bogus Microsoft Teams meeting invites to trick victims in key government and business sectors into handing over their authentication tokens, granting access to emails, cloud data, and other sensitive information.…