News
US elections have never been more secure, says CISA chief
Black Hat US Cybersecurity and Infrastructure Security Agency (CISA) director Jen Easterly and her counterparts from the UK and EU want the world to know that, when it comes to securing elections, they've never been more prepared.…
Report: Tech misconceptions plague the IT world
New research has shown that while many Brits will snap shut a laptop camera in the name of privacy, a worrying amount will just as happily shovel all manner of personal information into an online game in order to get a result they can share with their friends.…
Entrust faces years of groveling to regain browsers' trust, say rival chiefs
After falling down in the estimations of major browser makers Google and Mozilla, Entrust faces a lengthy fight on its hands to regain industry trust and once more issue trusted TLS certificates.…
Cloud storage lockers from Microsoft and Google used to store and spread state-sponsored malware
Black Hat State-sponsored cyber spies and criminals are increasingly using legitimate cloud services to attack their victims, according to Symantec's threat hunters who have spotted three such operations over recent months, plus new data theft and other malware tools in development by these goons.…
Samsung boosts bug bug bounty to a cool million for cracks of the Knox Vault subsystem
Samsung has dangled its first $1 million bug bounty for anyone who successfully compromises Knox Vault – the isolated subsystem the Korean giant bakes into its smartphones to store info like credentials and run authentication routines.…
Faulty instructions in Alibaba's T-Head C910 RISC-V CPUs blow away all security
Black Hat Computer security researchers at the CISPA Helmholtz Center for Information Security in Germany have found serious security flaws in some of Alibaba subsidiary T-Head Semiconductor's RISC-V processors.…
Fighting AI fire with AI fire
Sponsored Post Hackers and cyber criminals are busy finding new ways of using AI to launch attacks on businesses and organizations often unprepared to deal with the speed, scale and sophistication of the assaults directed against them.…
Small CSS tweaks can help nasty emails slip through Outlook's anti-phishing net
Researchers say cybercriminals can have fun bypassing one of Microsoft's anti-phishing measures in Outlook with some simple CSS tweaks.…
Police take just 2 days to recover $40M stolen in business email scam
Two days is all it took for Interpol to recover more than $40 million worth of stolen funds in a recent business email compromise (BEC) heist, the international cop shop said this week.…
EQT buys majority share in Swiss cybersecurity biz Acronis
Acronis, the Swiss disaster recovery turned cybersecurity firm and catch-all for managed service providers, has been majority acquired by Europe’s largest private equity firm, EQT.…
UK health services call-handling vendor faces $7.7M fine over 2022 ransomware attack
The UK's data protection watchdog says it plans to fine a managed software provider to the NHS £6.09 million ($7.7 million) for failings that led to a 2022 ransomware attack.…
SharpRhino malware targets IT admins – Hunters International gang suspected
The latest malware from upstart criminal gang Hunters International appears to be targeting network admins, using attack code disguised as the popular networking tool Angry IP Scanner.…
Georgia's voter portal gets a crash course in client versus backend input validation
The US state of Georgia has a website for cancelling voter registration, and it's had a bumpy start.…
Microsoft punches back at Delta Air Lines and its legal threats
Microsoft has labelled Delta Air Lines' accusations it's partly to blame for the outages caused by CrowdStrike’s buggy software "false" and "misleading" – and insulted the state of the carrier’s IT infrastructure.…
CrowdStrike hires outside security outfits to review troubled Falcon code
CrowdStrike has hired two outside security firms to review the Falcon functionality that sparked a global IT outage last month – but it may not have an awful lot to find, because CrowdStrike has identified the simple mistake that caused the meltdown.…
Google splats device-hijacking exploited-in-the-wild Android kernel bug among others
Google released 46 fixes for Android in its August security patch batch, including one for a Linux kernel flaw in the mobile OS that can lead to remote code execution (RCE).…
Sonic Automotive says ransomware-linked CDK software outage cost it $30M
One of the US's largest car dealerships says the IT outage caused by CDK Global's June ransomware attack cost it approximately $30 million.…
Bad apps bypass Windows security alerts for six years using newly unveiled trick
Elastic Security Labs has lifted the lid on a slew of methods available to attackers who want to run malicious apps without triggering Windows' security warnings, including one in use for six years.…
Users call on Microsoft to update Outlook's friendly name feature
Users are urging Microsoft to rethink how it shows sender email addresses in Outlook because phishing criminals are taking advantage, using helpful, friendly names to serve up emails loaded with malicious intent.…
Billion-dollar bust as international op shutters Cryptonator wallet
Users of Cryptonator – an online digital wallet and cryptocurrency exchange – received an unpleasant surprise last weekend after the service was shuttered in a combined operation run by the FBI, the US Internal Revenue Service (IRS), and German police.…