News

Incoming deputy head of Homeland Security says CISA needs to be reined in

The Register - Wed, 26/02/2025 - 02:31
Plus: New figurehead of DOGE emerges and they aren't called Elon

During confirmation hearings in the US Senate Tuesday for the role of deputy director of the Dept of Homeland Security, the nominee Troy Edgar said CISA has had the wrong management and needed to be "reined in."…

Categories: News

Drug-screening biz DISA took a year to disclose security breach affecting millions

The Register - Wed, 26/02/2025 - 00:05
If there's something nasty on your employment record, extortion scum could come calling

DISA Global Solutions, a company that provides drug and alcohol testing, background checks and other employee screening services, this week notified over 3.3 million people that their sensitive information may have been stolen by miscreants.…

Categories: News

Xi know what you did last summer: China was all up in Republicans' email, says book

The Register - Tue, 25/02/2025 - 21:39
Of course, Microsoft is in the mix, isn't it

Chinese spies reportedly broke into the US Republication National Committee's Microsoft-powered email and snooped around for months before being caught.…

Categories: News

MITRE Caldera security suite scores perfect 10 for insecurity

The Register - Tue, 25/02/2025 - 20:47
Is a trivial remote-code execution hole in every version part of the training, or?

The smart cookie who discovered a perfect 10-out-of-10-severity remote code execution (RCE) bug in MITRE's Caldera security training platform has urged users to "immediately pull down the latest version." As in, download it and install it.…

Categories: News

Harassment allegations against DEF CON veteran detailed in court filing

The Register - Tue, 25/02/2025 - 15:30
More than a dozen women came forward with accusations

Details about the harassment allegations leveled at DEF CON veteran Christopher Hadnagy have now been revealed after a motion for summary judgment was filed over the weekend.…

Categories: News

Data resilience and data portability

The Register - Tue, 25/02/2025 - 15:02
Why organizations should protect everything, everywhere, all at once

Sponsored Feature  Considering it has such a large share of the data protection market, Veeam doesn't talk much about backups in meetings with enterprise customers these days.…

Categories: News

China's Silver Fox spoofs medical imaging apps to hijack patients' computers

The Register - Tue, 25/02/2025 - 13:15
Sly like a PRC cyberattack

A Chinese government-backed group is spoofing legitimate medical software to hijack hospital patients' computers, infecting them with backdoors, credential-swiping keyloggers, and cryptominers.…

Categories: News

Malware variants that target operational tech systems are very rare – but 2 were found last year

The Register - Tue, 25/02/2025 - 11:00
Fuxnet and FrostyGoop were both used in the Russia-Ukraine war

Two new malware variants specifically designed to disrupt critical industrial processes were set loose on operational technology networks last year, shutting off heat to more than 600 apartment buildings in one instance and jamming communications to gas, water, and sewage network sensors in the other.…

Categories: News

Southern Water takes the fifth over alleged $750K Black Basta ransom offer

The Register - Tue, 25/02/2025 - 09:30
Leaked chats and spilled secrets as AI helps decode circa 200K private talks

Southern Water neither confirms nor denies offering Black Basta a $750,000 ransom payment following its ransomware attack in 2024.…

Categories: News

How nice that state-of-the-art LLMs reveal their reasoning ... for miscreants to exploit

The Register - Tue, 25/02/2025 - 07:34
Blueprints shared for jail-breaking models that expose their chain-of-thought process

Analysis  AI models like OpenAI o1/o3, DeepSeek-R1, and Gemini 2.0 Flash Thinking can mimic human reasoning through a process called chain of thought.…

Categories: News

Google binning SMS MFA at last and replacing it with QR codes

The Register - Tue, 25/02/2025 - 00:14
Everyone knew texted OTPs were a dud back in 2016

Google has confirmed it will phase out the use of SMS text messages for multi-factor authentication in favor of more secure technologies.…

Categories: News

US Dept of Housing screens sabotaged to show deepfake of Trump sucking Elon's toes

The Register - Mon, 24/02/2025 - 20:15
'Appropriate action will be taken,' we're told – as federal HR email sparks uproar, ax falls on CISA staff

Visitors to the US Department of Housing and Urban Development's headquarters in the capital got some unpleasant viewing on Monday morning after TV screens across the building began showing a deepfake video of President Trump kissing and sucking Elon Musk's toes.…

Categories: News

Shifting the cybersecurity odds

The Register - Mon, 24/02/2025 - 14:56
Four domains to build resilience

Partner Content  Security can feel like fighting a losing battle, but it doesn't have to be.…

Categories: News

The software UK techies need to protect themselves now Apple's ADP won’t

The Register - Mon, 24/02/2025 - 13:27
No matter how deep you are in Apple's 'ecosystem,’ there are ways to stay encrypted in the UK

Apple customers, privacy advocates, and security sleuths have now had the weekend to stew over the news of the iGadget maker's decision to bend to the UK government and disable its Advanced Data Protection (ADP) feature.…

Categories: News

Rather than add a backdoor, Apple decides to kill iCloud E2EE for UK peeps

The Register - Mon, 24/02/2025 - 03:31
PLUS: SEC launches new crypto crime unit; Phishing toolkit upgraded; and more

Infosec in brief  Apple has responded to the UK government's demand for access to its customers’ data stored in iCloud by deciding to turn off its Advanced Data Protection (ADP) end-to-end encryption service for UK users.…

Categories: News

Experts race to extract intel from Black Basta internal chat leaks

The Register - Fri, 21/02/2025 - 12:56
Researchers say there's dissent in the ranks. Plus: An AI tool lets you have a go yourself at analysing the data

Hundreds of thousands of internal messages from the Black Basta ransomware gang were leaked by a Telegram user, prompting security researchers to bust out their best Russian translations post haste.…

Categories: News

Ivanti endpoint manager can become endpoint ravager, thanks to quartet of critical flaws

The Register - Fri, 21/02/2025 - 06:51
PoC exploit code shows why this is a patch priority

Security engineers have released a proof-of-concept exploit for four critical Ivanti Endpoint Manager bugs, giving those who haven't already installed patches released in January extra incentive to revisit their to-do lists.…

Categories: News

Thailand ready to welcome 7,000 trafficked scam call center victims back from Myanmar

The Register - Fri, 21/02/2025 - 03:30
It comes amid a major crackdown on the abusive industry that started during COVID

Thailand is preparing to receive thousands of people rescued from scam call centers in Myanmar as the country launches a major crackdown on the pervasive criminal activity across its border.…

Categories: News

Linux royalty backs adoption of Rust for kernel code, says its rise is inevitable

The Register - Fri, 21/02/2025 - 00:38
Nobody wants memory bugs. Penguinistas continue debate on how to squish 'em

Some Linux kernel maintainers remain unconvinced that adding Rust code to the open source project is a good idea, but its VIPs are coming out in support of the language's integration.…

Categories: News

Microsoft expands Copilot bug bounty targets, adds payouts for even moderate messes

The Register - Thu, 20/02/2025 - 23:55
Said bugs 'can have significant implications' – glad to hear that from Redmond

Microsoft is so concerned about security in its Copilot products for folks that it’s lifted bug bounty payments for moderate-severity vulnerabilities from nothing to a maximum of $5,000, and expanded the range of vulnerabilities it will pay people to find and report.…

Categories: News

Pages

Subscribe to Sec Tec Limited aggregator - News