The Register - Anti-Virus

Syndikovat obsah
Biting the hand that feeds IT — Enterprise Technology News and Analysis
Aktualizace: 29 min 30 sek zpět

Ransomware can mean life or death at hospitals. DEF CON hackers to the rescue?

26 Březen, 2024 - 15:15
ARPA-H joins DARPA's AIxCC, adds $20M to cash rewards

Interview  As ransomware gangs target critical infrastructure – especially hospitals and other healthcare organizations – DARPA has added another government agency partner to its Artificial Intelligence Cyber Challenge (AIxCC).…

Kategorie: Viry a Červi

FreeBSD Foundation hands out Beacon gongs for safer software

26 Březen, 2024 - 12:15
Multiple CHERI-related projects win money for important research that prizes safety over speed

The inaugural Beacon Awards has handed three prizes to projects working on safer software for CHERI-enabled hardware running on the CheriBSD operating system.…

Kategorie: Viry a Červi

UK elections are unaffected by China's cyber-interference, says deputy PM

26 Březen, 2024 - 11:30
Sanctions galore for APT31, which has been blamed for two major attacks on democracy

The UK's deputy prime minister, Oliver Dowden, says China has been unsuccessful in its attempts to undermine UK elections.…

Kategorie: Viry a Červi

Row breaks out over true severity of two DNSSEC flaws

26 Březen, 2024 - 10:24
Some of us would be happy being rated 7.5 out of 10, just sayin'

Updated  Two DNSSEC vulnerabilities were disclosed last month with similar descriptions and the same severity score, but they are not the same issue.…

Kategorie: Viry a Červi

New Zealand to world: China attacked us, too!

26 Březen, 2024 - 05:30
Reveals 2021 incident that saw parliamentary agencies briefly probed

The government of South Pacific island nation New Zealand has revealed that it, too, has been attacked by China.…

Kategorie: Viry a Červi

US charges Chinese nationals with cyber-spying on pretty much everyone for Beijing

26 Březen, 2024 - 00:15
Plus: Alleged front sanctioned, UK blames PRC for Electoral Commission theft, and does America need a Cyber Force?

The United States on Monday accused seven Chinese men of breaking into computer networks, email accounts, and cloud storage belonging to numerous critical infrastructure organizations, companies, and individuals, including US businesses, politicians, and their political parties.…

Kategorie: Viry a Červi

Over 170K users caught up in poisoned Python package ruse

25 Březen, 2024 - 20:00
Supply chain attack targeted GitHub community of Top.gg Discord server

More than 170,000 users are said to have been affected by an attack using fake Python infrastructure with "successful exploitation of multiple victims."…

Kategorie: Viry a Červi

Tech trade union confirms cyberattack behind IT, email outage

25 Březen, 2024 - 17:31
Systems have been pulled offline as a precaution

Exclusive  The Communications Workers Union (CWU), which represents hundreds of thousands of employees in sectors across the UK economy including tech and telecoms, is currently working to mitigate a cyberattack.…

Kategorie: Viry a Červi

Mozilla fixes $100,000 Firefox zero-days following two-day hackathon

25 Březen, 2024 - 17:00
Users may have to upgrade twice to protect their browsers

Mozilla has swiftly patched a pair of critical Firefox zero-days after a researcher debuted them at a Vancouver cybersec competition.…

Kategorie: Viry a Červi

GoFetch security exploit can't be disabled on M1 and M2 Apple chips

25 Březen, 2024 - 16:30
For now, cryptographic work should be run on slower Icestorm cores

The GoFetch vulnerability found on Apple M-series and Intel Raptor Lake CPUs has been further unpacked by the researchers who first disclosed it.…

Kategorie: Viry a Červi

Time to examine the anatomy of the British Library ransomware nightmare

25 Březen, 2024 - 11:30
Mistakes years in the making tell a universal story that must not be ignored

Opinion  Quiz time: name one thing you know about the Library of Alexandria. Points deducted for "it’s a library. In Alexandria." Looking things up is cheating and you know it.…

Kategorie: Viry a Červi

That Asian meal you eat on holidays could launder money for North Korea

25 Březen, 2024 - 08:32
United Nations finds IT contract and crypto scams are just two of DPRK's illicit menu items

If you dine out at an Asian restaurant on your next holiday, the United Nations thinks your meal could help North Korea to launder money.…

Kategorie: Viry a Červi

Microsoft confirms memory leak in March Windows Server security update

25 Březen, 2024 - 03:15
ALSO: Viasat hack wiper malware is back, users are the number one cause of data loss, and critical vulns

Infosec in brief  If your Windows domain controllers have been crashing since a security update was installed earlier this month, there's no longer any need to speculate why: Microsoft has admitted it introduced a memory leak in its March patches and fixed the issue.…

Kategorie: Viry a Červi

Some 300,000 IPs vulnerable to this Loop DoS attack

24 Březen, 2024 - 20:37
Easy to exploit, not yet exploited, not widely patched – pick three

As many as 300,000 servers or devices on the public internet are thought to be vulnerable right now to the recently disclosed Loop Denial-of-Service technique that works against some UDP-based application-level services.…

Kategorie: Viry a Červi

Vans claims cyber crooks didn't run off with its customers' financial info

24 Březen, 2024 - 12:08
Just 35.5M names, addresses, emails, phone numbers … no biggie

Clothing and footwear giant VF Corporation is letting 35.5 million of its customers know they may find themselves victims of identity theft following last year's security breach.…

Kategorie: Viry a Červi

Russia's Cozy Bear caught phishing German politicos with phony dinner invites

23 Březen, 2024 - 09:51
Forget the Riesling, bring on the WINELOADER

The Kremlin's cyberspies targeted German political parties in a phishing campaign that used emails disguised as dinner party invitations, according to Mandiant.…

Kategorie: Viry a Červi

Chinese snoops use F5, ConnectWise bugs to sell access into top US, UK networks

23 Březen, 2024 - 00:02
Crew may well be working under contract for Beijing

Chinese spies exploited a couple of critical-severity bugs in F5 and ConnectWise equipment earlier this year to sell access to compromised US defense organizations, UK government agencies, and hundreds of other entities, according to Mandiant.…

Kategorie: Viry a Červi

3 million doors open to uninvited guests in keycard exploit

22 Březen, 2024 - 19:00
As months go by without fixes, hotels take the scenic route to securing rooms

Around 3 million doors protected by popular keycard locks are thought to be vulnerable to security flaws that allow miscreants to quickly slip into locked rooms.…

Kategorie: Viry a Červi

Hardware-level Apple Silicon vulnerability can leak cryptographic keys

22 Březen, 2024 - 17:03
Short of redesigning CPUs, the fix will seriously degrade performance

A side-channel vulnerability has been found in the architecture of Apple Silicon processors that gives malicious apps the ability to extract cryptographic keys from memory that should be off limits. …

Kategorie: Viry a Červi

NVD slowdown leaves thousands of vulnerabilities without analysis data

22 Březen, 2024 - 15:45
Security world reacts as NIST does a lot less of oft criticized, 'almost always thankless' work

Opinion  The United States National Institute of Standards and Technology (NIST) has almost completely stopped adding analysis to Common Vulnerabilities and Exposures (CVEs) listed in the National Vulnerability Database. That means big headaches for anyone using CVEs to maintain their security. …

Kategorie: Viry a Červi