Tag: The Register – Security

Cybersecurity professionals upskill in Brazil and Mexico

SANS Institute meets fast-growing demand for cyber security training in Latin America Sponsored Post  The scale of cybersecurity threats facing Latin America was brought into focus by recently when it published details of NICKEL, a “China-based threat actor”. The malware…

Ireland’s privacy watchdog fines WhatsApp €5.5 million

You’ve got 6 months to get into compliance, it tells yak-yak app Ireland’s data protection authority has fined WhatsApp Ireland €5.5 million for breaches of the GDPR relating to its service and told it comply with data processing laws within…

Crims steal data on 40 million T-Mobile US customers

Sixth snafu in five years? Crooks have this useless carrier on speed dial T-Mobile US today said someone abused an API to download the personal information of 37 million subscribers.… This article has been indexed from The Register – Security…

Ransomware severs 1,000 ships from on-shore servers

Get your eyepatch out: Cyber attacks on the high seas are trending A Norwegian maritime risk management business is getting a lesson in that very area, after a ransomware attack forced its ShipManager software offline and left 1,000 ships without…

Finally, ransomware victims are refusing to pay up

Dosh shelled out in 2022 dropped 40% over 2021, or so it says here The amount of money paid to ransomware attackers dropped significantly in 2022, and not because the number of attacks fell.… This article has been indexed from…

University of Texas latest US school to ban TikTok

Great, now staff and students can stop scrolling and get back to work Faculty and students at the University of Texas at Austin (UT) this week became the latest members of a public US university to lose access to Chinese…

Mailchimp ‘fesses up to second digital burglary in five months

Social engineering helped intruders break into customers’ inboxes again Email marketing service Mailchimp has confirmed intruders have gained access to more than 100 customer accounts after successfully deploying a social engineering attack.… This article has been indexed from The Register…

Period-tracking apps, search engines on notice by draft law

And no more geofencing around health clinics either A bill proposed by Washingston state lawmakers would make it illegal for period-tracking apps, Google or any other website to sell consumers’ health data while also making it harder for them to…

Tencent fired 100 people for corruption during 2022

A couple have already been jailed, others shown the door for embezzling or arranging sham contracts Chinese web and gaming giant Tencent has admitted it fired more than 100 people in 2022 for various forms of corruption – some so…

Russians say they can grab software from Intel again

And Windows updates from Microsoft, too People in Russia can reportedly once again download drivers and some other software from Intel and Microsoft, which both withdrew from the nation after its invasion of Ukraine.… This article has been indexed from…

Microsoft Defender ASR rules strip icons, app shortcuts from Taskbar

Happy Friday 13th sysadmins! Techies find workarounds but Redmond still ‘investigating’ Techies are reporting that Microsoft Defender for Endpoint attack surface reduction (ASR) rules have gone haywire and are removing icons and applications shortcuts from the Taskbar and Start Menu.……

Microsoft fumbles zero trust upgrade for some Asian customers

Enhanced access privileges for partners choke on double-byte characters, contribute to global delays Microsoft has messed up a zero trust upgrade its service provider partners have been asked to implement for customers.… This article has been indexed from The Register…

AI-generated phishing emails just got much more convincing

Did a criminally minded robot write this? In part, yes. GPT-3 language models are being abused to do much more than write college essays, according to WithSecure researchers.… This article has been indexed from The Register – Security Read the…

How to track equipped cars via exploitable e-ink platemaker

Miscreants could have tracked, modified, deleted digital plates California’s street-legal ink license plates only received a nod from the US government in October, but reverse engineers have already discovered vulnerabilities in the system allowing them to track each plate, reprogram…

Privacy on the line: Boffins break VoLTE phone security

Call metadata can be ferreted out Boffins based in China and the UK have devised a telecom network attack that can expose call metadata during VoLTE/VoNR conversations.… This article has been indexed from The Register – Security Read the original…

Russian meddling in 2016 US presidential election was weak sauce

Boffins find Twitter foreign influence campaign didn’t have much pull Russian disinformation didn’t materially affect the way people voted in the 2016 US presidential election, according to a research study published on Monday, though that doesn’t make the effect totally…

California e-ink platemaker exploited to track equipped cars

A bit of sloppy JSON let security folk track, modify and delete Reviver’s digital plates California’s street-legal ink license plates only received a nod from the US government in October, but reverse engineers have already discovered vulnerabilities in the system…

Homeland Security, CISA builds AI-based cybersecurity analytics sandbox

High-spec system is crucial to defending against the latest threats Two of the US government’s leading security agencies are building a machine learning-based analytics environment to defend against rapidly evolving threats and create more resilient infrastructures for both government entities…

DHS and CISA building an AI-based cybersecurity analytics sandbox

High-spec system is crucial to defending against the latest threats Two of the US government’s leading security agencies are building a machine learning-based analytics environment to defend against rapidly evolving threats and create more resilient infrastructures for both government entities…

US Supremes deny Pegasus spyware maker’s immunity claim

NSO maintains that it’s all legit The US Supreme Court has quashed spyware maker NSO Group’s argument that it cannot be held legally responsible for using WhatsApp technology to deploy its Pegasus snoop-ware on users’ phones.… This article has been…

Here’s how to remotely take over a Ferrari…account, that is

Connected cars. What could possibly go wrong? Multiple bugs affecting millions of vehicles from almost all major car brands could allow miscreants to perform any manner of mischief — in some cases including full takeovers —  by exploiting vulnerabilities in…

No more holidays for US telcos, FCC is cracking down

Also, LastPass faces class action, and Louisiana says that, while the internet may be for porn, ID is still required In Brief  The Federal Communications Commission plans to overhaul its security reporting rules for the telecom industry to, among other…

Here’s how to remotely takeover a Ferrari…account, that is

Connected cars. What could possible go wrong? Multiple bugs affecting millions of vehicles from almost all major car brands could allow miscreants to perform any manner of mischief — in some cases including full takeovers —  by exploiting vulnerabilities in…

Freedom for MegaCortex ransomware victims – the fix is out

Criminals hit 1,800 victims across 71 countries to the tune of $100m+ An international law enforcement effort has released a decryptor for victims of MegaCortex ransomware, widely used by cybercriminals to infect large corporations across 71 countries to the tune…

How to prioritize effectively with threat modeling

Crisis? What Crisis! Webinar  How does your security team prioritize work? When a new attack from a state actor hits the news, do you know if your team should drop everything to hunt for IOCs? Do you understand your security…

Rackspace blames ransomware woes on zero-day attack

Play gang blamed, ProxyNotShell cleared and hosted Exchange doomed Rackspace has confirmed the Play ransomware gang was behind last month’s hacking and said it won’t bring back its hosted Microsoft Exchange email service, as it continues working to recover customers’…

Twitter data dump: 200m+ account database now free to download

No passwords, but planety of stuff for social engineering and doxxing More than 200 million Twitter users’ information is now available for anyone to download for free.… This article has been indexed from The Register – Security Read the original…

PyTorch dependency poisoned with malicious code

System data was exfiltrated during attack, but an anonymous person says it was a research project gone wrong An unknown attacker used the PyPI code repository to get developers to download a compromised PyTorch dependency that included malicious code designed…

Google gets off easy in location tracking lawsuits

$29.5 million and we don’t have to admit wrongdoing? Where do we sign? Google has settled two more of the many location tracking lawsuits it had been facing over the past year, and this time the search giant is getting…

‘Multiple security breaches’ shut down trucker protest

10-7, there buddy, sorry An anti-government protest by truckers in Canada has been called off following “multiple security breaches,” according to organizers, who also cited “personal character attacks,” as a reason for the withdrawal.… This article has been indexed from The…

‘Multiple security breaches’ shut down Canadian trucker protest repeat

The Freedom Convoy ‘will remain Officially 10-7 until further notice’ An anti-government protest but truckers in Canada has been called off following “multiple security breaches,” according to organizers, who also cited “personal character attacks,” as a reason for the withdrawal.… This…