News

Signalgate lessons learned: If creating a culture of security is the goal, America is screwed

The Register - 17 hours 2 min ago
Infosec is a team sport … unless you're in the White House

Opinion  Just when it seems they couldn't be that careless, US officials tasked with defending the nation go and do something else that puts American critical infrastructure, national security, and troops' lives in danger.…

Categories: News

Amid CVE funding fumble, 'we were mushrooms, kept in the dark,' says board member

The Register - Fri, 25/04/2025 - 23:19
What next for US-bankrolled vulnerability tracker? It's edging closer to a more independent, global future

Kent Landfield, a founding member of the Common Vulnerabilities and Exposures (CVE) program and member of the board, learned through social media that the system he helped create was just hours away from losing funding.…

Categories: News

More Ivanti attacks may be on horizon, say experts who are seeing 9x surge in endpoint scans

The Register - Fri, 25/04/2025 - 20:00
GreyNoise says it is the kind of activity that typically precedes new vulnerability disclosures

Ivanti VPN users should stay alert as IP scanning for the vendor's Connect Secure and Pulse Secure systems surged by 800 percent last week, according to threat intel biz GreyNoise.…

Categories: News

Oh, cool. Microsoft melts bug that froze Server 2025 Remote Desktop sessions

The Register - Fri, 25/04/2025 - 19:00
Where have we heard this before? Feb security update needs its own fix

More than one month after complaints starting flying, Microsoft has fixed a Windows bug that caused some Remote Desktop sessions to freeze.…

Categories: News

M&S stops online orders as 'cyber incident' issues worsen

The Register - Fri, 25/04/2025 - 17:13
One step forward and one step back as earlier hopes of progress dashed by latest update

Marks & Spencer has paused online orders for customers via its website and app as the UK retailer continues to wrestle with an ongoing "cyber incident."…

Categories: News

Emergency patch for potential SAP zero-day that could grant full system control

The Register - Fri, 25/04/2025 - 16:31
German software giant paywalls details, but experts piece together the clues

SAP's latest out-of-band patch is for a perfect 10/10 bug in NetWeaver that experts suspect could have already been exploited as a zero-day.…

Categories: News

Claims assistance firm fined for cold-calling people who put themselves on opt-out list

The Register - Fri, 25/04/2025 - 10:29
Third-party data supplier also in hot water with Brit regulator over consent issues

Britain's data privacy watchdog has slapped a fine of £90k ($120k) on a business that targeted people with intrusive marketing phone calls, despite them being registered with the official "Do Not Call" opt-out service.…

Categories: News

Darcula adds AI to its DIY phishing kits to help would-be vampires bleed victims dry

The Register - Fri, 25/04/2025 - 07:18
Because coding phishing sites from scratch is a real pain in the neck

Darcula, a cybercrime outfit that offers a phishing-as-a-service kit to other criminals, this week added AI capabilities to its kit that help would-be vampires spin up phishing sites in multiple languages more efficiently.…

Categories: News

SSNs and more on 5.5M+ patients feared stolen from Yale Health

The Register - Thu, 24/04/2025 - 21:32
At least it wasn't Harvard

Yale New Haven Health has notified more than 5.5 million people that their private details were likely stolen by miscreants who broke into the healthcare system's network last month.…

Categories: News

Microsoft mystery folder fix might need a fix of its own

The Register - Thu, 24/04/2025 - 19:01
This one weird trick can stop Windows updates dead in their tracks

Turns out Microsoft's latest patch job might need a patch of its own, again. This time, the culprit is a mysterious inetpub folder quietly deployed by Redmond, now hijacked by a security researcher to break Windows updates.…

Categories: News

Assassin's Creed maker faces GDPR complaint for forcing single-player gamers online

The Register - Thu, 24/04/2025 - 16:59
Collecting data from solo players is a Far Cry from being necessary, says noyb

For anyone who's ever been frustrated by the need to go online to play a single-player video game, the European privacy specialists at noyb have heard you, and they've filed a complaint against Ubisoft in Austria dealing specifically with the issue. …

Categories: News

M&S takes systems offline as 'cyber incident' lingers

The Register - Thu, 24/04/2025 - 11:18
Customers told to expect further delays as contactless payments still down

UK high street retailer Marks & Spencer says contactless payments are still down following its "cyber incident" and order delays are likely to continue.…

Categories: News

Your vendor may be the weakest link: Percentage of third-party breaches doubled in a year

The Register - Thu, 24/04/2025 - 10:28
Cybercriminals are targeting software shops, accountants, lawyers

The percentage of confirmed data breaches involving third-party relationships doubled last year as cybercriminals increasingly exploited weak links in supply chains and partner ecosystems.…

Categories: News

Booby-trapped Alpine Quest Android app geolocates Russian soldiers

The Register - Thu, 24/04/2025 - 08:24
Back of the nyet!

Russian soldiers are being targeted with an Android app specially altered to pinpoint their location and scan their phones for files, with the ability to exfiltrate sensitive documents if instructed.…

Categories: News

Ransomware scum and other crims bilked victims out of a 'staggering' $16.6B last year, says FBI

The Register - Thu, 24/04/2025 - 01:51
Biggest threat to America's critical infrastructure? Ransomware

Digital scammers and extortionists bilked businesses and individuals in the US out of a "staggering" $16.6 billion last year, according to the FBI — the highest losses recorded since bureau’s Internet Crime Complaint Center (IC3) started tracking them 25 years ago.…

Categories: News

Blue Shield says it shared health info on up to 4.7M patients with Google Ads

The Register - Wed, 23/04/2025 - 23:18
Tech giants don't need smartphone mics to target adverts – your insurer just gives your data away, anyway

US health insurance giant Blue Shield of California handed sensitive health information belonging to as many as 4.7 million members to Google's advertising empire, likely without these individuals' knowledge or consent.…

Categories: News

Ripple NPM supply chain attack hunts for private keys

The Register - Wed, 23/04/2025 - 19:28
A mystery thief and a critical CVE involved in crypto cash grab

Many versions of the Ripple ledger (XRPL) official NPM package are compromised with malware injected to steal cryptocurrency.…

Categories: News

We’re calling it now: Agentic AI will win RSAC buzzword Bingo

The Register - Wed, 23/04/2025 - 18:41
All aboard the hype train

The security industry loves its buzzwords, and this is always on full display at the annual RSA Conference event in San Francisco. Don't believe us? Take a lap on the expo floor, and you'll be bombarded with enough acronyms and over-the-top claims to send you straight to the nearest bar, which will likely serve specialty cocktails with names like The Great CASB and Firewall Fizz.…

Categories: News

Who needs phishing when your login's already in the wild?

The Register - Wed, 23/04/2025 - 14:00
Stolen credentials edge out email tricks for cloud break-ins because they're so easy to get

Criminals used stolen credentials more frequently than email phishing to gain access into their victims' IT systems last year, marking the first time that compromised login details claimed the number two spot in Mandiant's list of most common initial infection vectors.…

Categories: News

Ex-NSA chief warns AI devs: Don’t repeat infosec’s early-day screwups

The Register - Wed, 23/04/2025 - 11:34
Bake in security now or pay later, says Mike Rogers

AI engineers should take a lesson from the early days of cybersecurity and bake safety and security into their models during development, rather than trying to bolt it on after the fact, according to former NSA boss Mike Rogers.…

Categories: News

Pages

Subscribe to Sec Tec Limited aggregator - News