Aims to get CVE logjam cleared by the end of FY 24 Facing a growing backlog of reported flaws, NIST has extended a commercial contract with an outside consultancy to help it get on top of its National Vulnerability Database…
Tag: The Register – Security
Crooks threaten to leak 3B personal records ‘stolen from background check firm’
Turns out opting out actually works? Billions of records detailing people’s personal information may soon be dumped online after being allegedly obtained from a Florida firm that handles background checks and other requests for folks’ private info.… This article has…
Russia takes gold for disinformation as Olympics approach
Featuring Tom Cruise deepfakes and multiple made-up terrorism threats Still throwing toys out the pram over its relationship with international sport, Russia is engaged in a multi-pronged disinformation campaign against the Olympic Games and host nation France that’s intensifying as…
Check Point warns customers to patch VPN vulnerability under active exploitation
Also, free pianos are the latest internet scam bait, Cooler Master gets pwned, and some critical vulnerabilities Infosec in brief Cybersecurity software vendor Check Point is warning customers to update their software immediately in light of a zero day vulnerability…
Derisking your CNI
How to strengthen cyber risk management for cyber physical systems (CPS) Webinar Can organizations ever scale back on the relentless task of identifying, prioritizing, and remediating vulnerabilities, and misconfigurations across their industrial and critical infrastructure environments?… This article has been…
Researchers crash Baidu robo-cars with tinfoil and paint daubed on cardboard
The fusion of Lidar, radar, and cameras can be fooled by stuff from your kids’ craft box A team of researchers from prominent universities – including SUNY Buffalo, Iowa State, UNC Charlotte, and Purdue – were able to turn an…
Twitch ditches Safety Advisory Council, relaunches with vetted ‘ambassadors’
Who needs experts when you have an army of hand-picked super users telling you what you want to hear? Twitch has reportedly dismantled its Safety Advisory Council, and apparently plans to replace the panel with chosen “ambassadors.”… This article has…
Snowflake denies miscreants melted its security to steal data from top customers
Infosec house claims Ticketmaster, Santander hit via cloud storage Infosec analysts at Hudson Rock believe Snowflake was compromised by miscreants who used that intrusion to steal data on hundreds of millions of people from Ticketmaster, Santander, and potentially other customers…
US senator claims UnitedHealth’s CEO, board appointed ‘unqualified’ CISO
Similar cases have resulted in serious sanctions, and they were on a far smaller scale Serial tech and digital privacy critic Senator Ron Wyden (D-OR) laid into UnitedHealth Group’s (UHG) CEO for appointing a CISO Wyden deemed “unqualified”– a decision…
Cyber cops plead for info on elusive Emotet mastermind
Follows arrests and takedowns of recent days After the big dog revelations from the past week, the cops behind Operation Endgame are now calling for help in tracking down the brains behind the Emotet operation.… This article has been indexed…
New Nork-ish cyberespionage outfit uncovered after three years
Sector-agnostic group is after your data, wherever you are Infosec researchers revealed today a previously unknown cybercrime group that’s been on the prowl for three years and is behaving like some of the more dangerous cyber baddies under Kim Jong-Un’s…
Google to push ahead with Chrome’s ad-blocker extension overhaul in earnest
Starting Monday, users will gradually be warned the end is near On Monday, June 3, 2024, some people using Beta, Dev, and Canary builds of Google’s Chrome browser will be presented with a warning banner when they access their extension…
FlyingYeti phishing crew grounded after abominable Ukraine attacks
Kremlin-aligned gang used Cloudflare and GitHub resources, and they didn’t like that one bit Cloudflare’s threat intel team claims to have thwarted a month-long phishing and espionage attack targeting Ukraine which it has attributed to Russia-aligned gang FlyingYeti.… This article…
Mystery miscreant remotely bricked 600,000 SOHO routers with malicious firmware update
Source and motive of ‘Pumpkin Eclipse’ assault unknown Unknown miscreants broke into more than 600,000 routers belonging to a single ISP late last year and deployed malware on the devices before totally disabling them, according to security researchers.… This article…
Mystery attacker remotely bricked 600,000 SOHO routers with malicious firmware update
Source and motive of ‘Pumpkin Eclipse’ attack unknown Unknown miscreants broke into more than 600,000 routers belonging to a single ISP late last year and deployed malware on the devices before totally disabling them, according to security researchers.… This article…
OpenAI is very smug after thwarting five ineffective AI covert influence ops
That said, use of generative ML to sway public opinion may not always be weak sauce OpenAI on Thursday said it has disrupted five covert influence operations that were attempting to use its AI services to manipulate public opinion and…
US Treasury says NFTs ‘highly susceptible’ to fraud, but ignored by high-tier criminals
Narco kingpins aren’t coming for your apes, but internet con artists still are The US Treasury Department has assessed the risk of non-fungible tokens (NFTs) being used for illicit finance, and has found them wanting for lack of proper roadblocks…
Euro cops disrupt malware droppers, seize thousands of domains
Operation Endgame just beginning: ‘Stay tuned,’ says Europol An international law enforcement operation led by Europol has kicked off with the announcement of multiple arrests, searches, seizures and takedowns of malware droppers and their operators.… This article has been indexed…
Cybercriminals raid BBC pension database, steal records of over 25,000 people
This just in: We lost your personal info, but here’s 2 years’ worth of Experian The BBC has emailed more than 25,000 current and former employees on one of its pension schemes after an unauthorized party broke into a database…
IT worker sued over ‘vengeful’ cyber harassment of policeman who issued a jaywalking ticket
His hospital employer is also being sued for not stepping in sooner In an ongoing civil lawsuit, an IT worker is accused of launching a “destructive cyber campaign of hate and revenge” against a police officer and his family after…