News

The software UK techies need to protect themselves now Apple's ADP won’t

The Register - Mon, 24/02/2025 - 13:27
No matter how deep you are in Apple's 'ecosystem,’ there are ways to stay encrypted in the UK

Apple customers, privacy advocates, and security sleuths have now had the weekend to stew over the news of the iGadget maker's decision to bend to the UK government and disable its Advanced Data Protection (ADP) feature.…

Categories: News

Rather than add a backdoor, Apple decides to kill iCloud E2EE for UK peeps

The Register - Mon, 24/02/2025 - 03:31
PLUS: SEC launches new crypto crime unit; Phishing toolkit upgraded; and more

Infosec in brief  Apple has responded to the UK government's demand for access to its customers’ data stored in iCloud by deciding to turn off its Advanced Data Protection (ADP) end-to-end encryption service for UK users.…

Categories: News

Experts race to extract intel from Black Basta internal chat leaks

The Register - Fri, 21/02/2025 - 12:56
Researchers say there's dissent in the ranks. Plus: An AI tool lets you have a go yourself at analysing the data

Hundreds of thousands of internal messages from the Black Basta ransomware gang were leaked by a Telegram user, prompting security researchers to bust out their best Russian translations post haste.…

Categories: News

Ivanti endpoint manager can become endpoint ravager, thanks to quartet of critical flaws

The Register - Fri, 21/02/2025 - 06:51
PoC exploit code shows why this is a patch priority

Security engineers have released a proof-of-concept exploit for four critical Ivanti Endpoint Manager bugs, giving those who haven't already installed patches released in January extra incentive to revisit their to-do lists.…

Categories: News

Thailand ready to welcome 7,000 trafficked scam call center victims back from Myanmar

The Register - Fri, 21/02/2025 - 03:30
It comes amid a major crackdown on the abusive industry that started during COVID

Thailand is preparing to receive thousands of people rescued from scam call centers in Myanmar as the country launches a major crackdown on the pervasive criminal activity across its border.…

Categories: News

Linux royalty backs adoption of Rust for kernel code, says its rise is inevitable

The Register - Fri, 21/02/2025 - 00:38
Nobody wants memory bugs. Penguinistas continue debate on how to squish 'em

Some Linux kernel maintainers remain unconvinced that adding Rust code to the open source project is a good idea, but its VIPs are coming out in support of the language's integration.…

Categories: News

Microsoft expands Copilot bug bounty targets, adds payouts for even moderate messes

The Register - Thu, 20/02/2025 - 23:55
Said bugs 'can have significant implications' – glad to hear that from Redmond

Microsoft is so concerned about security in its Copilot products for folks that it’s lifted bug bounty payments for moderate-severity vulnerabilities from nothing to a maximum of $5,000, and expanded the range of vulnerabilities it will pay people to find and report.…

Categories: News

Oops, some of our customers' Power Pages sites were exploited, says Microsoft

The Register - Thu, 20/02/2025 - 23:17
Don't think this is SaaS and you can relax: Redmond wants a few of you to check your websites

Microsoft has fixed a security flaw in its Power Pages website-building SaaS, after criminals got there first – and urged users to check their sites for signs of exploitation.…

Categories: News

US minerals company says crooks broke into email and helped themselves to $500K

The Register - Thu, 20/02/2025 - 16:44
A painful loss for young company that's yet to generate revenue

A NASDAQ-listed US minerals company says cybercriminals broke into its systems on Valentine's Day and paid themselves around $500,000 – money earmarked for a vendor.…

Categories: News

Critical flaws in Mongoose library expose MongoDB to data thieves, code execution

The Register - Thu, 20/02/2025 - 14:45
Bugs fixed, updating to the latest version is advisable

Security sleuths found two critical vulnerabilities in a third-party library that MongoDB relies on, which means bad guys can potentially steal data and run code.…

Categories: News

Two arrested after pensioner scammed out of six-figure crypto nest egg

The Register - Thu, 20/02/2025 - 11:35
The latest in a long line of fraud stings worth billions each year

Two men are in police custody after being arrested in connection with a July cryptocurrency fraud involving a man in his seventies.…

Categories: News

Ghost ransomware crew continues to haunt IT depts with scarily bad infosec

The Register - Thu, 20/02/2025 - 08:41
FBI and CISA issue reminder - deep sigh - about the importance of patching and backups

The operators of Ghost ransomware continue to claim victims and score payments, but keeping the crooks at bay is possible by patching known vulnerabilities and some basic infosec actions, according to a joint advisory issued Wednesday by the FBI and US Cybersecurity and Infrastructure Security Agency.…

Categories: News

Medusa ransomware gang demands $2M from UK private health services provider

The Register - Thu, 20/02/2025 - 07:34
2.3 TB held to ransom as biz formerly known as Virgin Care tells us it's probing IT 'security incident'

Exclusive  HCRG Care Group, a private health and social services provider, has seemingly fallen victim to the Medusa ransomware gang, which is threatening to leak what's claimed to be stolen internal records unless a substantial ransom is paid.…

Categories: News

US Army soldier linked to Snowflake extortion rampage admits breaking the law

The Register - Thu, 20/02/2025 - 03:01
That's the way the cookie melts

A US Army soldier suspected of hacking AT&T and Verizon has admitted leaking online people's private call records.…

Categories: News

Trump’s DoD CISO pick previously faced security clearance suspension

The Register - Wed, 19/02/2025 - 22:00
Hey, at least Katie Arrington brings a solid resume

Donald Trump's nominee for a critical DoD cybersecurity role sports a resume that outshines many of his past picks, despite previously suspended security clearance.…

Categories: News

Check out this free automated tool that hunts for exposed AWS secrets in public repos

The Register - Wed, 19/02/2025 - 20:45
You can find out if your GitHub codebase is leaking keys ... but so can miscreants

A free automated tool that lets anyone scan public GitHub repositories for exposed AWS credentials has been released.…

Categories: News

Hundreds of Dutch medical records bought for pocket change at flea market

The Register - Wed, 19/02/2025 - 13:01
15GB of sensitive files traced back to former software biz

Typically shoppers can expect to find tie-dye t-shirts, broken lamps and old disco records at flea markets, now it seems storage drives filled with huge volumes of sensitive data can be added to that list.…

Categories: News

London celebrity talent agency reports itself to ICO following Rhysida attack claims

The Register - Wed, 19/02/2025 - 09:30
Showbiz members' passport scans already plastered online

A London talent agency has reported itself to the UK's data protection watchdog after the Rhysida ransomware crew last week claimed it had attacked the business, which represents luminaries of stage and screen.…

Categories: News

Healthcare outfit that served military personnel settles allegations it faked infosec compliance for $11 million

The Register - Wed, 19/02/2025 - 01:14
If this makes you feel sick, knowing this happened before ransomware actors started targeting medical info may help

An alleged security SNAFU that occurred during the Obama administration has finally been settled under the second Trump administration.…

Categories: News

Palo Alto firewalls under attack as miscreants chain flaws for root access

The Register - Wed, 19/02/2025 - 00:15
If you want to avoid urgent patches, stop exposing management consoles to the public internet

A flaw patched last week by Palo Alto Networks is now under active attack and, when chained with two older vulnerabilities, allows attackers to gain root access to affected systems.…

Categories: News

Pages

Subscribe to Sec Tec Limited aggregator - News