14 Jan

Miscreants ‘mass exploited’ Fortinet firewalls, ‘highly probable’ zero-day used

Miscreants running a “mass exploitation campaign” against Fortinet firewalls, which peaked in December, may be using an unpatched zero-day vulnerability to compromise the equipment, according

Author rabih
13 Jan

Cryptojacking, backdoors abound as fiends abuse Aviatrix Controller bug

“Several cloud deployments” are already compromised following the disclosure of the maximum-severity vulnerability in Aviatrix Controller, researchers say. CVE-2024-50603 leads to remote code execution (RCE)

Author rabih
13 Jan

Microsoft sues ‘foreign-based’ cyber-crooks, seizes sites used to abuse AI

Microsoft has sued a group of unnamed cybercriminals who developed tools to bypass safety guardrails in its generative AI tools. The tools were used to

Author rabih
13 Jan

Azure, Microsoft 365 MFA outage locks out users across regions

Microsoft’s multi-factor authentication (MFA) for Azure and Microsoft 365 (M365) was offline for four hours during Monday’s busy start for European subscribers. “Multi-Factor Authentication (MFA)

Author rabih
13 Jan

NATO’s newest member comes out swinging following latest Baltic Sea cable attack

Sweden has committed to sending naval forces into the Baltic Sea following yet another suspected Russian attack on underwater cables in the region. The deployment

Author rabih
13 Jan

Ransomware crew abuses AWS native encryption, sets data-destruct timer for 7 days

A new ransomware crew dubbed Codefinger targets AWS S3 buckets and uses the cloud giant’s own server-side encryption with customer provided keys (SSE-C) to lock

Author rabih
13 Jan

Nominet probes network intrusion linked to Ivanti zero-day exploit

UK domain registrar Nominet is investigating a potential intrusion into its network related to the latest Ivanti zero-day exploits. Nominet told customers via an email

Author rabih
13 Jan

Europe coughs up €400 to punter after breaking its own GDPR data protection rules

Infosec in brief Gravy Analytics, a vendor of location intelligence info for marketers which reached a settlement with US authorities last year over its alleged

Author rabih
10 Jan

Chinese cyber-spies peek over shoulder of officials probing real-estate deals near American military bases

Chinese cyber-spies who broke into the US Treasury Department also stole documents from officials investigating real-estate sales near American military bases, it’s reported. Citing three

Author rabih
10 Jan

Drug addiction treatment service admits attackers stole sensitive patient data

BayMark Health Services, one of the biggest drug addiction treatment facilities in the US, says it is notifying some patients this week that their sensitive

Author rabih
10 Jan

Devs sent into security panic by ‘feature that was helpful … until it wasn’t’

On Call Velkomin, Vælkomin, Hoş geldin, and welcome to Friday, and therefore to another edition of On Call – The Register‘s end-of-week celebration of the

Author rabih
09 Jan

Look for the label: White House rolls out ‘Cyber Trust Mark’ for smart devices

The White House this week introduced a voluntary cybersecurity labeling program for technology products so that consumers can have some assurance their smart devices aren’t

Author rabih
09 Jan

Zero-day exploits plague Ivanti Connect Secure appliances for second year running

The cybersecurity industry is urging those in charge of defending their orgs to take mitigation efforts “seriously” as Ivanti battles two dangerous new vulnerabilities, one

Author rabih
09 Jan

Security pros baited with fake Windows LDAP exploit traps

Security researchers are once again being lured into traps by attackers, this time with fake exploits of serious Microsoft security flaws. Trend Micro spotted what

Author rabih
09 Jan

Crypto is soaring, but so are threats: Here’s how to keep your wallet safe

Digital Security As detections of cryptostealers surge across Windows, Android and macOS, it’s time for a refresher on how to keep your bitcoin or other

Author rabih
09 Jan

Japanese Police claim China ran five-year cyberattack campaign targeting local orgs

Japan’s National Police Agency and Center of Incident Readiness and Strategy for Cybersecurity have confirmed third party reports of attacks on local orgs by publishing

Author rabih
09 Jan

Japanese Police claim China ran five-year cyberattack campaign

Japan’s National Police Agency and Center of Incident Readiness and Strategy for Cybersecurity have confirmed third party reports of attacks on local orgs by publishing

Author rabih
09 Jan

I tried hard, but didn’t fix all of cybersecurity, admits outgoing US National Cyber Director

The outgoing leader of the United States’ Office of the National Cyber Director has a clear message for whomever President-elect Trump picks to be his

Author rabih
Load moreLoadingAll items loaded