News

Securing open source software: Whose job is it, anyway?

The Register - Fri, 08/03/2024 - 01:02
CISA announces more help, and calls on app makers to step up

The US government and some of the largest open source foundations and package repositories have announced a series of initiatives intended to improve software supply-chain security, while also repeating calls for developers to increase support for such efforts.…

Categories: News

We're not Meta support: State AGs tell Zuck to fix rampant account takeover problem

The Register - Thu, 07/03/2024 - 21:45
'We refuse to operate as customer service representatives'

A group of 41 US state attorneys general, tired of serving as a customer complaint clearinghouse for Facebook and Instagram users, have sent a letter to Meta asking it to figure out how to reduce a "dramatic and persistent spike" in account takeovers.…

Categories: News

Chrome users – get an alert when extensions are in danger of falling into wrong hands

The Register - Thu, 07/03/2024 - 19:45
Under New Management is an early-warning system for potential poisoning of add-ons with malware

Millions of Chrome users now have a way to guard against the threat of extension subversion, that is, if they don't mind installing yet another browser extension.…

Categories: News

Possible China link to Change Healthcare ransomware attack

The Register - Thu, 07/03/2024 - 18:30
Alleged crim bought SmartScreen Killer, Cobalt Strike on dark-web markets

A criminal claiming to be an ALPHV/BlackCat affiliate — the gang responsible for the widely disruptive Change Healthcare ransomware infection last month —  may have ties to Chinese government-backed cybercrime syndicates.…

Categories: News

JetBrains TeamCity under attack by ransomware thugs after disclosure mess

The Register - Thu, 07/03/2024 - 16:34
More than 1,000 servers remain unpatched and vulnerable

Security researchers are increasingly seeing active exploit attempts using the latest vulnerabilities in JetBrains' TeamCity that in some cases are leading to ransomware deployment.…

Categories: News

Belgian ale legend Duvel’s brewery borked as ransomware halts production

The Register - Thu, 07/03/2024 - 12:45
Company reassures public it has enough beer, expects quick recovery before weekend

Belgian beer brewer Duvel says a ransomware attack has brought its facility to a standstill while its IT team works to remediate the damage.…

Categories: News

VMware urges emergency action to blunt hypervisor flaws

The Register - Thu, 07/03/2024 - 07:30
Critical vulns in USB under ESXi and desktop hypervisors found by Chinese researchers at cracking contest

Hypervisors are supposed to provide an inviolable isolation layer between virtual machines and hardware. But hypervisor heavyweight VMware by Broadcom yesterday revealed its hypervisors are not quite so inviolable as it might like.…

Categories: News

Here’s something else AI can do: expose bad infosec to give cyber-crims a toehold in your organization

The Register - Thu, 07/03/2024 - 06:27
Singaporean researchers note rising presence of ChatGPT creds in Infostealer malware logs

Stolen ChatGPT credentials are a hot commodity on the dark web, according to Singapore-based threat intelligence firm Group-IB, which claims to have found some 225,000 stealer logs containing login details for the service last year.…

Categories: News

US lawmakers want ByteDance to divest TikTok or face a ban

The Register - Thu, 07/03/2024 - 06:05
The American mind must not be at the mercy of Chinese algorithms

A group of US lawmakers introduced legislation on Tuesday that, if passed, would force Chinese internet concern ByteDance to divest TikTok – its most valuable property – or see it banned in the US.…

Categories: News

Lawsuit claims gift card fraud is the gift that keeps on giving, to Google

The Register - Thu, 07/03/2024 - 01:15
Play Store commissions are a nice little earner, wherever they come from

Google has been accused of profiting from gift card scams.…

Categories: News

Chinese chap charged with stealing Google’s AI datacenter secrets

The Register - Thu, 07/03/2024 - 00:37
Moonlighted for PRC companies after side-stepping Big G's security, allegedly

A now-former Google employee has been charged with stealing the ad giant’s AI trade secrets while quietly working for two Chinese companies – after easily defeating whatever security controls Big G had in place.…

Categories: News

FBI: Critical infrastructure suffers spike in ransomware attacks

The Register - Wed, 06/03/2024 - 20:49
Jump in overall cybercrime reports, $60M-plus reportedly lost to extortionists alone, Feds reckon

Digital crimes potentially cost victims more than $12.5 billion last year, according to the FBI's latest Internet Crime Complaint Center (IC3) annual report. …

Categories: News

Apple's trademark tight lips extend to new iPhone, iPad zero-days

The Register - Wed, 06/03/2024 - 17:01
Two flaws fixed, one knee bent to the EU, and a budding cybersecurity star feature in iOS 17.4

Apple's latest security patches address four vulnerabilities affecting iOS and iPadOS, including two zero-days that intel suggests attackers have already exploited.…

Categories: News

Capita says 2023 cyberattack costs a factor as it reports staggering £100M+ loss

The Register - Wed, 06/03/2024 - 12:31
Additional cuts announced, sparking fears of further layoffs

Outsourcing giant Capita today reported a net loss of £106.6 million ($135.6 million) for calendar 2023, with the costly cyberattack by criminals making a hefty dent in its annual financials.…

Categories: News

Chip lobby group SEMI to EU: Export restrictions should only be used in self-defense

The Register - Wed, 06/03/2024 - 08:23
Please don't scare away foreign investors - who do you think pays for this stuff?

SEMI, an industry association representing 3,000 chip vendors, would really appreciate it if the European Union would back off plans to impose export controls on China, arguing that they should only be used as a "last resort" to protect national security.…

Categories: News

Japan orders local giants LINE and NAVER to disentangle their tech stacks

The Register - Wed, 06/03/2024 - 03:29
Government mighty displeased about a shared Active Directory that led to a big data leak

Japan's government has ordered local tech giants LINE and NAVER to disentangle their tech stacks, after a data breach saw over 510,000 users' data exposed.…

Categories: News

Uncle Sam intervenes as Change Healthcare ransomware fiasco creates mayhem

The Register - Wed, 06/03/2024 - 00:30
As the crooks behind the attack - probably ALPHV/BlackCat - fake their own demise

The US government has stepped in to help hospitals and other healthcare providers affected by the Change Healthcare ransomware infection, offering more relaxed Medicare rules and urging advanced funding to providers.…

Categories: News

Fidelity customers' financial info feared stolen in suspected ransomware attack

The Register - Tue, 05/03/2024 - 19:28
Insurance giant blames Infosys, LockBit claims credit

Criminals have probably stolen nearly 30,000 Fidelity Investments Life Insurance customers' personal and financial information — including bank account and routing numbers, credit card numbers and security or access codes — after breaking into Infosys' IT systems in the fall.…

Categories: News

US accuses Army vet cyber-Casanova of sharing Russia-Ukraine war secrets

The Register - Tue, 05/03/2024 - 17:06
Where better to expose confidential data than on a dating app?

Yet another US military man is facing a potentially significant stretch in prison after allegedly sending secret national defense information (NDI) overseas.…

Categories: News

IP address X-posure now a feature on Musk's social media platform

The Register - Tue, 05/03/2024 - 16:18
If you're still on X you'd better disable this insecure-by-default calling feature, lest someone snatch your IP

Video and audio calling features for X Premium users added last year to Elon Musk's version of Twitter have been expanded to everyone on the platform, and we're warning Reg readers yet again to disable the feature - this time because it appears to expose user IP addresses.…

Categories: News

Pages

Subscribe to Sec Tec Limited aggregator - News