News

Fake IT support calls hit 20 orgs, end in stolen Salesforce data and extortion, Google warns

The Register - Wed, 04/06/2025 - 16:05
Victims include hospitality, retail and education sectors

A group of financially motivated cyberscammers who specialize in Scattered-Spider-like fake IT support phone calls managed to trick employees at about 20 organizations into installing a modified version of Salesforce's Data Loader that allows the crims to steal sensitive data.…

Categories: News

Crims stole 40,000 people's data from our network, admits publisher Lee Enterprises

The Register - Wed, 04/06/2025 - 14:35
Did somebody say ransomware? Not the newspaper group, not even to deny it

Regional newspaper publisher Lee Enterprises says data belonging to around 40,000 people was stolen during an attack on its network earlier this year.…

Categories: News

UK CyberEM Command to spearhead new era of armed conflict

The Register - Wed, 04/06/2025 - 10:21
Government details latest initiative following announcement last week

Revealing more details about the Cyber and Electromagnetic (CyberEM) military domain, the UK's Ministry of Defence (MoD) says "there are pockets of excellence" but improvements must be made to ensure the country's capability meets the needs of national defense.…

Categories: News

Ukraine war spurred infosec vet Mikko Hyppönen to pivot to drones

The Register - Wed, 04/06/2025 - 08:30
Why? There's a war in Europe, Finland has a belligerent neighbor, and cyber is a settled field

Interview  Mikko Hyppönen has spent the last 34 years creating security software that defends against criminals and state-backed actors, but now he's moving onto drone warfare.…

Categories: News

‘Deliberate attack’ deletes shopping app’s AWS and GitHub resources

The Register - Wed, 04/06/2025 - 04:58
CEO of India's KiranaPro, which brings convenience stores online, vows to name the perp

The CEO of Indian grocery ordering app KiranaPro has claimed an attacker deleted its GitHub and AWS resources in a targeted and deliberate attack and vowed to name the perpetrator.…

Categories: News

Meta pauses mobile port tracking tech on Android after researchers cry foul

The Register - Wed, 04/06/2025 - 00:18
Zuckercorp and Yandex used localhost loophole to tie browser data to app users, say boffins

Security researchers say Meta and Yandex used native Android apps to listen on localhost ports, allowing them to link web browsing data to user identities and bypass typical privacy protections.…

Categories: News

You say Cozy Bear, I say Midnight Blizzard, Voodoo Bear, APT29 …

The Register - Tue, 03/06/2025 - 23:21
Microsoft, CrowdStrike, and pals promise clarity on cybercrew naming, deliver alias salad instead

Opinion  Microsoft and CrowdStrike made a lot of noise on Monday about teaming up with other threat-intel outfits to "bring clarity to threat-actor naming."…

Categories: News

Google quietly pushes emergency fix for Chrome 0-day as exploit runs wild

The Register - Tue, 03/06/2025 - 20:23
TAG team spotted the V8 bug first, so you can bet nation-states weren’t far behind

Google revealed Monday that it had quietly deployed a configuration change last week to block active exploitation of a Chrome zero-day.…

Categories: News

X's new 'encrypted' XChat feature seems no more secure than the failure that came before it

The Register - Tue, 03/06/2025 - 19:02
Musk's 'Bitcoin-style encryption' claim has experts scratching their heads

Elon Musk's X social media platform is rolling out a new version of its direct messaging feature that the platform owner said had a "whole new architecture," but as with many a Muskian proclamation, there's reason to doubt what's been said. …

Categories: News

Crooks fleece The North Face accounts with recycled logins

The Register - Tue, 03/06/2025 - 18:39
Outdoorsy brand blames credential stuffing

Joining the long queue of retailers dealing with cyber mishaps is outdoorsy fashion brand The North Face, which says crooks broke into some customer accounts using login creds pinched from breaches elsewhere.…

Categories: News

Microsoft patches the patch that put Windows 11 in a coma

The Register - Tue, 03/06/2025 - 14:33
Out-of-band is becoming the norm rather than the exception

Microsoft is patching another patch that dumped some PCs into recovery mode with an unhelpful error code.…

Categories: News

Illicit crypto-miners pouncing on lazy DevOps configs that leave clouds vulnerable

The Register - Tue, 03/06/2025 - 12:23
To stop the JINX-0132 gang behind these attacks, pay attention to HashiCorp, Docker, and Gitea security settings

Up to a quarter of all cloud users are at risk of having their computing resources stolen and used to illicitly mine for cryptocurrency, after crims cooked up a campaign that targets publicly accessible DevOps tools.…

Categories: News

Bling slinger Cartier tells customers to be wary of phishing attacks after intrusion

The Register - Tue, 03/06/2025 - 10:52
Nothing terribly valuable taken in data heist, though privacy a little tarnished

Global jewelry giant Cartier is writing to customers to confirm their data was exposed to cybercriminals that broke into its systems.…

Categories: News

Ukrainians smuggle drones hidden in cabins on trucks to strike Russian airfields

The Register - Mon, 02/06/2025 - 21:04
A real-world Trojan Horse attack

Ukraine claims it launched a cunning drone strike on Sunday against multiple Russian airbases, hitting over 40 military aircraft and inflicting an estimated $7 billion in damage, in an operation dubbed "Spiderweb."…

Categories: News

US community bank says thieves drained customer data through third party hole

The Register - Mon, 02/06/2025 - 13:27
Disclosure at MainStreet Bancshares comes as American finance orgs beg for looser reporting requirements

Community bank MainStreet Bancshares says thieves stole data belonging to some of its customers during an attack on a third-party provider.…

Categories: News

Lumma infostealer takedown may have inflicted only a flesh wound as crew keeps pinching and selling data

The Register - Mon, 02/06/2025 - 02:16
PLUS: Ransomware gang using tech support scam; Czechia accuses China of infrastructure attack; And more!

Infosec In Brief  Despite last week’s FBI announcement that it helped to take down the crew behind the Lumma infostealer, the malware continues to operate.…

Categories: News

Mysterious leaker GangExposed outs Conti kingpins in massive ransomware data dump

The Register - Sat, 31/05/2025 - 11:23
'It's a high-stakes intelligence war' he told El Reg

exclusive  A mystery whistleblower calling himself GangExposed has exposed key figures behind the Conti and Trickbot ransomware crews, publishing a trove of internal files and naming names.…

Categories: News

ConnectWise customers get mysterious warning about 'sophisticated' nation-state hack

The Register - Fri, 30/05/2025 - 20:01
Pen tester on ScreenConnect bug: This one ‘terrifies’ me

ConnectWise has brought in the big guns to investigate a "sophisticated nation state actor" that broke into its IT environment and then breached some of its customers.…

Categories: News

Feds arrest DoD techie, claim he dumped top secret files in park for foreign spies to find

The Register - Fri, 30/05/2025 - 19:29
28-year-old alleged to have made multiple drops to folks who turned out to be undercover FBI agents

A Defense Intelligence Agency (DIA) IT specialist is scheduled to appear in court today after being caught by the FBI trying to surreptitiously drop top secret information to a foreign government in a public park.…

Categories: News

US medical org pays $50M+ to settle case after crims raided data and threatened to swat cancer patients

The Register - Fri, 30/05/2025 - 18:35
Cash splashed on damages, infrastructure improvements, and fraud monitoring

A Seattle cancer facility has agreed to fork out around $52.5 million as part of a class action settlement linked to a Thanksgiving 2023 cyberattack where criminals directly threatened cancer patients with swat attacks.…

Categories: News

Pages

Subscribe to Sec Tec Limited aggregator - News