Tag: The Register – Security

Delinea Secret Server customers should apply latest patches

Attackers could nab an org’s most sensitive keys if left unaddressed Customers of Delinea’s Secret Server are being urged to upgrade their installations “immediately” after a researcher claimed a critical vulnerability could allow attackers to gain admin-level access.… This article…

US senator wants to put the brakes on Chinese EVs

Fears of low-cost invasion and data spies spark call for ban Electric vehicles may become a new front in America’s tech war with China after a US senator called for Washington DC to block Chinese-made EVs to protect domestic industries…

Identifying third-party risk

The prima facie case for real-time threat intelligence Webinar  Cybercriminals are always on the hunt for new ways to breach your privacy, and busy supply chains often look like a good way to get in under the wire.… This article…

Turning the tide on third-party risk

Using threat intelligence to mitigate against security breaches Webinar  There are some unhappy projections out there about the prevalence of third-party security breaches.… This article has been indexed from The Register – Security Read the original article: Turning the tide…

Feds probe alleged classified US govt data theft and leak

State Dept keeps schtum ‘for security reasons’ Updated  Uncle Sam is investigating claims that some miscreant stole and leaked classified information from the Pentagon and other national security agencies.… This article has been indexed from The Register – Security Read…

When AI attacks

Watch this webinar for a hair raising journey into the darkest depths of GenAI enabled cyber crime Sponsored Post  Artificial intelligence (AI) offers enormous commercial potential but also substantial risks to data security if it is harnessed by cyber criminals…

Security pioneer Ross Anderson dies at 67

A man with a list of accolades long enough for several lifetimes, friends remember his brilliance Obituary  Venerable computer scientist and information security expert Ross Anderson has died at the age of 67.… This article has been indexed from The…

OWASP server blunder exposes decade of resumes

Irony alerts: Open Web Application Security Project Foundation suffers lapse A misconfigured MediaWiki web server allowed digital snoops to access members’ resumes containing their personal details at the Open Web Application Security Project (OWASP) Foundation.… This article has been indexed…

OWASP breach exposes decade of resumes due to misconfigured server

Irony alerts: Open Web Application Security Project Foundation suffers lapse A misconfigured MediaWiki web server allowed digital snoops to access members’ resumes containing their personal details at the Open Web Application Security Project (OWASP) Foundation.… This article has been indexed…

Pandabuy admits to data breach of 1.3 million unique records

Nothing says ‘sorry’ like 10 percent off shipping for a month Ecommerce platform Pandabuy has apologized after two cybercriminals were spotted hawking personal data belonging to 1.3 million customers.… This article has been indexed from The Register – Security Read…

Six banks share customer info to help Singapore fight money laundering

PLUS: Google Cloud ANZ boss departs; Japan revives airliner ambitions; China-linked attackers target Asian entities ASIA IN BRIEF  Singapore’s Monetary Authority on Monday launched an application, intuitively named “COllaborative Sharing of Money Laundering/TF Information & Cases” (COSMIC for short, obviously)…

Malicious xz backdoor reveals fragility of open source

This time, we got lucky. It mostly affected bleeding-edge distros. But that’s not a defense strategy Analysis  The discovery last week of a backdoor in a widely used open source compression library called xz could have been a security disaster…

Nvidia’s newborn ChatRTX bot patched for security bugs

Flaws enable privilege escalation and remote code execution Nvidia’s AI-powered ChatRTX app launched just six week ago but already has received patches for two security vulnerabilities that enabled attack vectors, including privilege escalation and remote code execution.… This article has…

Apple fans deluged with phony password reset requests

Beware support calls offering a fix Apple device owners, consider yourselves warned: a targeted multi-factor authentication bombing campaign is under way, with the goal of exhausting iUsers into allowing an unwanted password reset.… This article has been indexed from The…

Apple fans flooded with phony password reset requests

Beware support calls offering a fix Apple device owners, consider yourselves warned: A targeted multi-factor authentication bombing campaign is going around with the goal of exhausting iUsers into accidentally allowing a password reset.… This article has been indexed from The…

Majority of Americans now use ad blockers

We’re dreaming of a white list, because we’re just like the ones you used to know More than half of Americans are using ad blocking software, and among advertising, programming, and security professionals that fraction is more like two-thirds to…

The easy road to pervasive DLP

How Forcepoint Data Security Everywhere does what it says on the tin Sponsored Post  The coronavirus pandemic appears to have changed the employment landscape forever, with estimates suggesting that up to a quarter of staff still spend some of their…

FreeBSD Foundation hands out Beacon gongs for safer software

Multiple CHERI-related projects win money for important research that prizes safety over speed The inaugural Beacon Awards has handed three prizes to projects working on safer software for CHERI-enabled hardware running on the CheriBSD operating system.… This article has been…

New Zealand to world: China attacked us, too!

Reveals 2021 incident that saw parliamentary agencies briefly probed The government of South Pacific island nation New Zealand has revealed that it, too, has been attacked by China.… This article has been indexed from The Register – Security Read the…

Over 170K users caught up in poisoned Python package ruse

Supply chain attack targeted GitHub community of Top.gg Discord server More than 170,000 users are said to have been affected by an attack using fake Python infrastructure with “successful exploitation of multiple victims.”… This article has been indexed from The…

Over 170K users hit by poisoned Python package ruse

Supply chain attack targeted GitHub community of Top.gg Discord server More than 170,000 users have been affected by an attack using fake Python infrastructure with “successful exploitation of multiple victims.”… This article has been indexed from The Register – Security…

Tech trade union confirms cyberattack behind IT, email outage

Systems have been pulled offline as a precaution Exclusive  The Communications Workers Union (CWU), which represents hundreds of thousands of employees in sectors across the UK economy including tech and telecoms, is currently working to mitigate a cyberattack.… This article…