Keynotes, physical security, playlists … the buck stops with Linda Gray Martin Interview The 33rd RSA Conference is underway this week, and no one feels that more acutely than the cybersecurity event’s SVP Linda Gray Martin.… This article has been…
Tag: The Register – Security
UnitedHealth’s ‘egregious negligence’ led to Change Healthcare ransomware infection
‘I’m blown away by the fact that they weren’t using MFA’ Interview The cybersecurity practices that led up to the stunning Change Healthcare ransomware infection indicate “egregious negligence” on the part of parent company UnitedHealth, according to Tom Kellermann, SVP…
UnitedHealth’s ‘egregious negligence’ led to Change Healthcare infection
‘I’m blown away by the fact that they weren’t using MFA’ Interview The cybersecurity practices that led up to the stunning Change Healthcare ransomware infection indicate “egregious negligence” on the part of parent company UnitedHealth, according to Tom Kellermann, SVP…
America’s War on Drugs and Crime will be AI powered, says Homeland Security boss
Or at least it might well be if these trial programs work out, with some civil lib oversight etc etc etc RSAC AI is a double-edged sword in that the government can see ways in which the tech can protect…
Watch out for rogue DHCP servers decloaking your VPN connections
Avoid traffic-redirecting snoops who have TunnelVision A newly discovered vulnerability undermines countless VPN clients in that their traffic can be quietly routed away from their encrypted tunnels and intercepted by snoops on the network.… This article has been indexed from…
CISA’s early-warning system helped critical orgs close 852 ransomware holes
In the first year alone, that’s saved us all a lot of money and woe RSAC As ransomware gangs step up their attacks against healthcare, schools, and other US critical infrastructure, CISA is ramping up a program to help these…
TikTok sues America to undo divest-or-die law
Nothing like folks in Beijing lecturing us on the Constitution TikTok and its China-based parent ByteDance sued the US government today to prevent the forced sale or shutdown of the video-sharing giant.… This article has been indexed from The Register…
Cops finally unmask ‘LockBit kingpin’ after two-month tease
Dmitry Yuryevich Khoroshev’s $10M question is answered at last Updated Police have finally named who they firmly believe is the kingpin of the LockBit ransomware ring: Dmitry Yuryevich Khoroshev.… This article has been indexed from The Register – Security Read…
Investigators finally unmask LockBit kingpin after two-month tease
Dmitry Yuryevich Khoroshev’s $10M question is answered at last The kingpin of the LockBit ransomware operation has finally been named by law enforcement as Dmitry Yuryevich Khoroshev.… This article has been indexed from The Register – Security Read the original…
The truth about KEV: CISA’s vuln deadlines good influence on private-sector patching
More work to do as most deadlines are missed and worst bugs still take months to fix The deadlines associated with CISA’s Known Exploited Vulnerabilities (KEV) catalog only apply to federal agencies, but fresh research shows they’re having a positive…
Physical security biz exposes 1.2M files via unprotected database
Thousands of guards’ ID cards and CCTV snaps of suspects found online Exclusive A UK-based physical security business let its guard down, exposing nearly 1.3 million documents via a public-facing database, according to an infosec researcher.… This article has been…
Ransomware evolves from mere extortion to ‘psychological attacks’
Crims SIM swap execs’ kids to freak out their parents, Mandiant CTO says RSAC Ransomware infections and extortion attacks have become “a psychological attack against the victim organization,” as criminals use increasingly personal and aggressive tactics to force victims to…
Google, Meta, Spotify break Apple’s device fingerprinting rules – new claim
And the iOS titan doesn’t seem that bothered with this data leaking out Last week, Apple began requiring iOS developers justify the use of a specific set of APIs that could be used for device fingerprinting. Yet the iGiant doesn’t…
Fed-run LockBit site back from the dead and vows to really spill the beans on gang
After very boring first reveal, this could be the real deal Cops around the world have relaunched LockBit’s website after they shut it down in February – and it’s now counting down the hours to reveal documents that could unmask…
Mastodon delays firm fix for link previews DDoSing sites
Decentralization is great until everyone wants to grab data from your web server Updated Mastodon has pushed back an update that’s expected to fully address the issue of link previews sparking accidental distributed denial of service (DDoS) attacks.… This article…
Mastodon delays fix for link previews DDoSing websites
Decentralization is great, except when many servers grab data from a site Mastodon has pushed back an update that would have addressed the issue of link previews creating accidental distributed denial of service (DDoS) attacks.… This article has been indexed…
Consultant charged over $1.5M extortion scheme against IT giant
Accused of stealing data after losing his job A cybersecurity expert could face a 20-year prison sentence after being accused of allegedly trying to extort a multinational IT infrastructure services biz out of $1.5 million.… This article has been indexed…
CISA says ‘no more’ to decades-old directory traversal bugs
Recent attacks on healthcare thrust infosec agency into alert mode CISA is calling on the software industry to stamp out directory traversal vulnerabilities following recent high-profile exploits of the 20-year-old class of bugs.… This article has been indexed from The…
Germany points finger at Fancy Bear for widespread 2023 hacks, DDoS attacks
ALSO: Microsoft promises to git gud on cybersecurity; unqualified attackers are targeting your water systems, and more infosec in brief It was just around a year ago that a spate of allegedly Russian-orchestrated cyberattacks hit government agencies in Germany, and…
End-to-end encryption may be the bane of cops, but they can’t close that Pandora’s Box
Internet Society’s Robin Wilton tells us the war on privacy won’t be won by the plod interview Police can complain all they like about strong end-to-end encryption making their jobs harder, but it doesn’t matter because the technology is here…