‘It’s not our job to find the culprits – That’s what we’re paying you for’ lawmaker scolds Brad Smith Lawmakers on Thursday grilled Microsoft president Brad Smith about the Windows giant’s businesses dealing in China — and the super-corp’s repeated…
Category: The Register – Security
US Space Force wanted $77M to reinforce GPS – and Congress shot it down
Can’t we do this another way, like without these mini-sats costing $1B over 5 years, House reps wonder A plan by America’s Space Force to harden GPS against spoofing attacks may be going nowhere: A request by the service branch…
Oracle Ads have had it: $2B operation shuts down after dwindling to $300M
In this slightly more private era, your data ain’t as profitable as it once was Analysis Oracle Advertising is shutting down, CEO Safra Catz said during the database goliath’s fiscal 2024 Q4 earnings call with Wall Street this week.… This…
Ukrainian cops collar Kyiv programmer believed to be Conti, LockBit linchpin
28-year-old accused of major ransomware attacks across Europe An alleged cog in the Conti and LockBit ransomware machines is now in handcuffs after Ukrainian police raided his home this week.… This article has been indexed from The Register – Security…
Google’s Privacy Sandbox more like a privacy mirage, campaigners claim
Chocolate Factory accused of misleading Chrome browser users Privacy campaigner noyb has filed a GDPR complaint regarding Google’s Privacy Sandbox, alleging that turning on a “Privacy Feature” in the Chrome browser resulted in unwanted tracking by the US megacorp.… This…
Student’s flimsy bin bags blamed for latest NHS data breach
Confidential patient information found by member of the public A data protection gaffe affecting the UK’s NHS is being pinned on a medical student who placed too much trust in their bin bags.… This article has been indexed from The…
Time to zero in on Zero Trust?
Recently discovered vulnerabilities in VPN services should push ASEAN organizations to rethink their perimeter security approach Sponsored Post Companies the ASEAN region have long relied on a virtual private network (VPN) to help encrypt their Internet traffic and protect users’…
Crooks crack customer info at tracking device vendor Tile, issue ‘extortion’ demands
Who tracks the trackers? Life360, purveyor of “Tile” Bluetooth tracking devices and developer of associated apps, has revealed it is dealing with a “criminal extortion attempt” after unknown miscreants contacted it with an allegation they had customer data in their…
Ransomware crew may have exploited Windows make-me-admin bug as a zero-day
Symantec suggests Black Basta crew beat Microsoft to the patch The Black Basta ransomware gang may have exploited a now-patched Windows privilege escalation bug as a zero-day, according to Symantec’s threat hunters.… This article has been indexed from The Register…
White House report dishes deets on all 11 major government breaches from 2023
The MOVEit breach and ransomware weren’t kind to the Feds last year The number of cybersecurity incidents reported by US federal agencies rose 9.9 percent year-on-year (YoY) in 2023 to a total of 32,211, per a new White House report,…
China’s FortiGate attacks more extensive than first thought
Dutch intelligence says at least 20,000 firewalls pwned in just a few months The Netherlands’ cybersecurity agency (NCSC) says the previously reported attack on the country’s Ministry of Defense (MoD) was far more extensive than previously thought.… This article has…
Let’s kick off our summer with a pwn-me-by-Wi-Fi bug in Microsoft Windows
Redmond splats dozens of bugs as does Adobe while Arm drivers and PHP under active attack Patch Tuesday Microsoft kicked off our summer season with a relatively light June Patch Tuesday, releasing updates for 49 CVE-tagged security flaws in its…
Pure Storage pwned, claims data plundered by crims who broke into Snowflake workspace
Secure storage company hasn’t spilled details on how they got in Pure Storage is the latest company to confirm it’s a victim of mounting Snowflake-related data breaches.… This article has been indexed from The Register – Security Read the original…
Cylance clarifies data breach details, except where the data came from
Customers, partners, operations remain uncompromised, BlackBerry says BlackBerry-owned cybersecurity shop Cylance says the data allegedly belonging to it and being sold on a crime forum doesn’t endanger customers, yet it won’t say where the information was stored originally.… This article…
UK and Canada’s data chiefs join forces to investigate 23andMe mega-breach
Three-pronged approach aims to uncover any malpractice at the Silicon Valley biotech biz The data protection watchdogs of the UK and Canada are teaming up to hunt down the facts behind last year’s 23andMe data breach.… This article has been…
Snowflake customers not using MFA are not unique – over 165 of them have been compromised
Mandiant warns criminal gang UNC5537, which may be friendly with Scattered Spider, is on the rampage An unknown financially motivated crime crew has swiped a “significant volume of records” from Snowflake customers’ databases using stolen credentials, according to Mandiant.… This…
Cyber attack flattens Japanese vid-sharing site Niconico and others
Total rebuild needed after four days off the air Japanese media conglomerate Kadokawa and several of its properties have been offline for four days after a major cyber attack.… This article has been indexed from The Register – Security Read…
Christie’s confirms RansomHub crooks stole data on 45K clients
A far cry from the half-million claim that crims originally boasted Auction house to the wealthy Christie’s says 45,798 people were affected by its recent cyberattack and resulting data theft.… This article has been indexed from The Register – Security…
Snowflake tells customers to enable MFA as investigations continue
Also, industry begs Uncle Sam for infosec reg harmony, dueling container-compromise campaigns, and crit vulns infosec in brief Cloud data analytics platform Snowflake said it is going to begin forcing customers to implement multi-factor authentication to prevent more intrusions. … This…
Two arrested in UK over fake cell tower-powered smishing campaign
Thousands of dodgy SMS messages bypassed network filters in UK-first case British police have arrested two individuals following an investigation into illegal homebrew phone masts used for SMS-based phishing campaigns.… This article has been indexed from The Register – Security…