Category: The Register – Security

Crims steal data on 40 million T-Mobile US customers

Sixth snafu in five years? Crooks have this useless carrier on speed dial T-Mobile US today said someone abused an API to download the personal information of 37 million subscribers.… This article has been indexed from The Register – Security…

Ransomware severs 1,000 ships from on-shore servers

Get your eyepatch out: Cyber attacks on the high seas are trending A Norwegian maritime risk management business is getting a lesson in that very area, after a ransomware attack forced its ShipManager software offline and left 1,000 ships without…

Finally, ransomware victims are refusing to pay up

Dosh shelled out in 2022 dropped 40% over 2021, or so it says here The amount of money paid to ransomware attackers dropped significantly in 2022, and not because the number of attacks fell.… This article has been indexed from…

Mailchimp ‘fesses up to second digital burglary in five months

Social engineering helped intruders break into customers’ inboxes again Email marketing service Mailchimp has confirmed intruders have gained access to more than 100 customer accounts after successfully deploying a social engineering attack.… This article has been indexed from The Register…

Russians say they can grab software from Intel again

And Windows updates from Microsoft, too People in Russia can reportedly once again download drivers and some other software from Intel and Microsoft, which both withdrew from the nation after its invasion of Ukraine.… This article has been indexed from…

How to track equipped cars via exploitable e-ink platemaker

Miscreants could have tracked, modified, deleted digital plates California’s street-legal ink license plates only received a nod from the US government in October, but reverse engineers have already discovered vulnerabilities in the system allowing them to track each plate, reprogram…

Privacy on the line: Boffins break VoLTE phone security

Call metadata can be ferreted out Boffins based in China and the UK have devised a telecom network attack that can expose call metadata during VoLTE/VoNR conversations.… This article has been indexed from The Register – Security Read the original…

California e-ink platemaker exploited to track equipped cars

A bit of sloppy JSON let security folk track, modify and delete Reviver’s digital plates California’s street-legal ink license plates only received a nod from the US government in October, but reverse engineers have already discovered vulnerabilities in the system…

DHS and CISA building an AI-based cybersecurity analytics sandbox

High-spec system is crucial to defending against the latest threats Two of the US government’s leading security agencies are building a machine learning-based analytics environment to defend against rapidly evolving threats and create more resilient infrastructures for both government entities…

US Supremes deny Pegasus spyware maker’s immunity claim

NSO maintains that it’s all legit The US Supreme Court has quashed spyware maker NSO Group’s argument that it cannot be held legally responsible for using WhatsApp technology to deploy its Pegasus snoop-ware on users’ phones.… This article has been…

No more holidays for US telcos, FCC is cracking down

Also, LastPass faces class action, and Louisiana says that, while the internet may be for porn, ID is still required In Brief  The Federal Communications Commission plans to overhaul its security reporting rules for the telecom industry to, among other…

Rackspace blames ransomware woes on zero-day attack

Play gang blamed, ProxyNotShell cleared and hosted Exchange doomed Rackspace has confirmed the Play ransomware gang was behind last month’s hacking and said it won’t bring back its hosted Microsoft Exchange email service, as it continues working to recover customers’…

PyTorch dependency poisoned with malicious code

System data was exfiltrated during attack, but an anonymous person says it was a research project gone wrong An unknown attacker used the PyPI code repository to get developers to download a compromised PyTorch dependency that included malicious code designed…

‘Multiple security breaches’ shut down trucker protest

10-7, there buddy, sorry An anti-government protest by truckers in Canada has been called off following “multiple security breaches,” according to organizers, who also cited “personal character attacks,” as a reason for the withdrawal.… This article has been indexed from The…