Cybersecurity and other IT news aggregator

LATEST FEEDS

  • French Authorities Launch Operation to Remove PlugX Malware from Infected Systems

    French Authorities Launch Operation to Remove PlugX Malware from Infected Systems 2024-07-27 at 10:01 By French judicial authorities, in collaboration with Europol, have launched a so-called “disinfection operation” to rid compromised hosts of a known malware called PlugX. The Paris Prosecutor’s Office, Parquet de Paris, said the initiative was launched on July 18 and that…


  • Malicious PyPI Package Targets macOS to Steal Google Cloud Credentials

    Malicious PyPI Package Targets macOS to Steal Google Cloud Credentials 2024-07-27 at 09:01 By Cybersecurity researchers have discovered a malicious package on the Python Package Index (PyPI) repository that targets Apple macOS systems with the goal of stealing users’ Google Cloud credentials from a narrow pool of victims. The package, named “lr-utils-lib,” attracted a total…


  • No, really, please ban Chinese DJI drones from America’s skies, senators asked

    No, really, please ban Chinese DJI drones from America’s skies, senators asked 2024-07-27 at 01:01 By Matthew Connatser Previous outlawing attempt flew off, will this one stick the landing? US senators have been asked again to consider banning the use of drones made by Chinese manufacturer DJI in American airspace after a previous attempt to…


  • Kamala Harris’ $7M support from LinkedIn founder comes with a request: Fire Lina Khan

    Kamala Harris’ $7M support from LinkedIn founder comes with a request: Fire Lina Khan 2024-07-27 at 00:16 By Brandon Vigliarolo FTC boss must be doing something right if folks will pay to get her binned LinkedIn cofounder Reid Hoffman was quick to express support for Kamala Harris’ bid for the US presidency this year after…


  • Video game actors strike because they fear an attack of the AI clones

    Video game actors strike because they fear an attack of the AI clones 2024-07-26 at 23:31 By Brandon Vigliarolo You wouldn’t download a performer Actors are back on strike for an entirely unsurprising reason: Studios aren’t willing to give video game actors enough protection from artificial intelligence. … This article is an excerpt from The Register…


  • iPhone kicked out of China’s top 5 smartphone brands as domestic market bounces back

    iPhone kicked out of China’s top 5 smartphone brands as domestic market bounces back 2024-07-26 at 22:31 By Matthew Connatser Chinese brands ascendant in the country’s phone market, but Apple’s exile might only be temporary For the first time in a while, the top five smartphone vendors in China are all native, with Apple’s position…


  • CrowdStrike meets Murphy’s Law: Anything that can go wrong will

    CrowdStrike meets Murphy’s Law: Anything that can go wrong will 2024-07-26 at 21:46 By Steven J. Vaughan-Nichols And boy, did last Friday’s Windows fiasco ever prove that yet again Opinion  CrowdStrike’s recent Windows debacle will surely earn a prominent place in the annals of epic tech failures. On July 19, the cybersecurity giant accomplished what…


  • SpaceX Falcon 9 set for comeback after upper-stage failure

    SpaceX Falcon 9 set for comeback after upper-stage failure 2024-07-26 at 20:46 By Richard Speed Cracked line blamed for leak SpaceX aims to resume launching the Falcon 9 rocket tomorrow after the Federal Aviation Administration (FAA) agreed to let the company return to flight operations.… This article is an excerpt from The Register View Original…


  • Ledger Flex: Secure self-custody with E Ink touchscreen display

    Ledger Flex: Secure self-custody with E Ink touchscreen display 2024-07-26 at 20:16 By Industry News Ledger today launched Ledger Flex, featuring secure E Ink touchscreen displays powered by Ledger’s Secure OS. It’s available to purchase for $249, shipping immediately. The Ledger Flex features a high-resolution, 2.8” display that provides clarity when signing transactions or approving…


  • Intel nabs Micron exec to oversee foundry business ambitions

    Intel nabs Micron exec to oversee foundry business ambitions 2024-07-26 at 19:46 By Dan Robinson Memory veteran to help Gelsinger and co with longstanding internal/external contract manufacturing plans Intel is set to hire an executive from memory chipmaker Micron to head its foundry biz as the company pursues its strategy of turning its former internal…


  • Are deepfake fraud risks overhyped? Where enterprises are exposed

    Are deepfake fraud risks overhyped? Where enterprises are exposed 2024-07-26 at 19:16 By Will deepfakes become the number one avenue for fraudsters to steal money? Likely not. This article is an excerpt from Subscribe to Security Magazine’s RSS Feed View Original Source React to this headline:


  • Happy Sysadmin Day, the Bitlocker keys are in a bowl on top of the fridge

    Happy Sysadmin Day, the Bitlocker keys are in a bowl on top of the fridge 2024-07-26 at 18:46 By Team Register Vote below for the best way to celebrate our underappreciated heroes Seven days after CrowdStrike’s bad update took down Windows-based computers around the world, System Administrator Appreciation Day has arrived. And what lovely gifts…


  • Wave of Cyberattacks Target Greece’s Land Registry Dept

    Wave of Cyberattacks Target Greece’s Land Registry Dept 2024-07-26 at 18:05 Greece’s Land Registry Department, also known as the Hellenic Cadastre, has faced over 400 cyberattacks within a week. These attacks, aimed at compromising the agency’s IT infrastructure, resulted in a limited data breach. Hackers stole 1.2 GB of data from employee terminals — only…


  • IAM for MSPs Provider Evo Security Raises $6 Million

    IAM for MSPs Provider Evo Security Raises $6 Million 2024-07-26 at 17:46 By Ionut Arghire TechOperators leads a $6 million Series A funding round for Evo Security, a provider of IAM solutions for MSPs. The post IAM for MSPs Provider Evo Security Raises $6 Million appeared first on SecurityWeek. This article is an excerpt from…


  • Progress Patches Critical Telerik Report Server Vulnerability

    Progress Patches Critical Telerik Report Server Vulnerability 2024-07-26 at 17:46 By Ionut Arghire Progress Software calls attention to a critical remote code execution flaw in the Telerik Report Server product. The post Progress Patches Critical Telerik Report Server Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source…


  • Boeing Starliner crew get their ISS sleepover extended

    Boeing Starliner crew get their ISS sleepover extended 2024-07-26 at 17:31 By Richard Speed Bosses regret talking up mission duration as Capsule’s lifetime extended to 90 days The crew of the Boeing Starliner will spend the summer aboard the International Space Station (ISS) as NASA and Boeing refused to set a return date for the…


  • Progress discloses second critical flaw in Telerik Report Server in as many months

    Progress discloses second critical flaw in Telerik Report Server in as many months 2024-07-26 at 16:46 By Connor Jones These are the kinds of bugs APTs thrive on, just ask the Feds Progress Software’s latest security advisory warns customers about the second critical vulnerability targeting its Telerik Report Server in as many months.… This article…


  • This AI-Powered Cybercrime Service Bundles Phishing Kits with Malicious Android Apps

    This AI-Powered Cybercrime Service Bundles Phishing Kits with Malicious Android Apps 2024-07-26 at 16:46 By A Spanish-speaking cybercrime group named GXC Team has been observed bundling phishing kits with malicious Android applications, taking malware-as-a-service (MaaS) offerings to the next level. Singaporean cybersecurity company Group-IB, which has been tracking the e-crime actor since January 2023, described…


  • ‘A moose hit me’ and other ways people damage their gizmos

    ‘A moose hit me’ and other ways people damage their gizmos 2024-07-26 at 16:01 By Dan Robinson The wild world of wrecking our tech Have you ever bitten your phone, or thrown it in anger? How about broken it in a collision with a moose? These are just some of the ways in which people…


  • Is it Time to Rethink Your Security Stack?

    Is it Time to Rethink Your Security Stack? 2024-07-26 at 16:01 By The cybersecurity threat landscape is constantly evolving, requiring organizations to regularly evaluate their security stack to ensure it not only offers the highest level of protection, but is operated by a firm with a long track record of developing, implementing, and properly maintaining…


  • Threat Actors Exploit Fresh ServiceNow Vulnerabilities in Attacks

    Threat Actors Exploit Fresh ServiceNow Vulnerabilities in Attacks 2024-07-26 at 15:31 By Ionut Arghire Threat actors have started exploiting critical-severity vulnerabilities in ServiceNow shortly after public disclosure. The post Threat Actors Exploit Fresh ServiceNow Vulnerabilities in Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source React to…


  • Starting a job in tech? Read this advice to maximize your experience

    Starting a job in tech? Read this advice to maximize your experience 2024-07-26 at 15:16 By There are steps that graduates can take to make the transition from school into a Security Operations Center as smooth as possible. This article is an excerpt from Subscribe to Security Magazine’s RSS Feed View Original Source React to…


  • Google DeepMind’s latest models kinda sorta take silver at Math Olympiad

    Google DeepMind’s latest models kinda sorta take silver at Math Olympiad 2024-07-26 at 14:46 By Tobias Mann Sure, it took three days to do what teenaged brainiacs do in nine hours – but who’s counting? Researchers at Google DeepMind claim they’ve developed a pair of AI models capable of taking home a silver medal in…


  • Offensive AI: The Sine Qua Non of Cybersecurity

    Offensive AI: The Sine Qua Non of Cybersecurity 2024-07-26 at 14:16 By “Peace is the virtue of civilization. War is its crime. Yet it is often in the furnace of war that the sharpest tools of peace are forged.” – Victor Hugo. In 1971, an unsettling message started appearing on several computers that comprised ARPANET,…


  • In Other News: FBI Cyber Action Team, Pentagon IT Firm Leak, Nigerian Gets 12 Years in Prison

    In Other News: FBI Cyber Action Team, Pentagon IT Firm Leak, Nigerian Gets 12 Years in Prison 2024-07-26 at 14:01 By SecurityWeek News Noteworthy stories that might have slipped under the radar: FBI article on agency’s Cyber Action Team, data of Pentagon IT provider Leidos leaked, Nigerian cybercriminal sentenced to 12 years in prison. The…


  • US Offers $10 Million Reward for Information on North Korean Hacker

    US Offers $10 Million Reward for Information on North Korean Hacker 2024-07-26 at 14:01 By Ionut Arghire The US is offering a reward of up to $10 million for information on Rim Jong Hyok, a member of the North Korean hacking group APT45. The post US Offers $10 Million Reward for Information on North Korean…


  • UK.gov to chuck up to £5B to gang of back office software vendors

    UK.gov to chuck up to £5B to gang of back office software vendors 2024-07-26 at 13:46 By Lindsay Clark Framework deal set to run until 2029 as central govt transitions to new ERP SaaS model The UK government has gone to market shopping for back office software in a tender which could be worth up…


  • PKfail Vulnerability Allows Secure Boot Bypass on Hundreds of Computer Models 

    PKfail Vulnerability Allows Secure Boot Bypass on Hundreds of Computer Models  2024-07-26 at 13:01 By Eduard Kovacs A vulnerability dubbed PKfail can allow attackers to run malicious code during the boot process, which can be used to deliver UEFI bootkits. The post PKfail Vulnerability Allows Secure Boot Bypass on Hundreds of Computer Models  appeared first…


  • Shuttle Columbia’s near-miss: Why we should always expect the unexpected in space

    Shuttle Columbia’s near-miss: Why we should always expect the unexpected in space 2024-07-26 at 12:46 By Richard Speed The eventful launch of STS-93 and the Chandra X-Ray Observatory Twenty-five years ago, Space Shuttle Columbia launched the Chandra X-ray observatory and nearly ended in catastrophe. As the then-ascent flight director John Shannon observed: “Yikes. We don’t…


  • U.S. DoJ Indicts North Korean Hacker for Ransomware Attacks on Hospitals

    U.S. DoJ Indicts North Korean Hacker for Ransomware Attacks on Hospitals 2024-07-26 at 12:01 By The U.S. Department of Justice (DoJ) on Thursday unsealed an indictment against a North Korean military intelligence operative for allegedly carrying out ransomware attacks against healthcare facilities in the country and funneling the payments to orchestrate additional intrusions into defense,…


  • 97% of Devices Disrupted by CrowdStrike Restored as Insurer Estimates Billions in Losses

    97% of Devices Disrupted by CrowdStrike Restored as Insurer Estimates Billions in Losses 2024-07-26 at 11:17 By Eduard Kovacs CrowdStrike says 97% of Windows systems impacted by its bad update are back online, just as an insurer predicts billions in losses for major companies. The post 97% of Devices Disrupted by CrowdStrike Restored as Insurer…


  • Study shock! AI hinders productivity and makes working worse

    Study shock! AI hinders productivity and makes working worse 2024-07-26 at 09:46 By Thomas Claburn Management drank the Kool Aid but staff can’t cope with new demands Bosses expect artificial intelligence software to improve productivity, but workers say the tool does the opposite, according to a survey by find-a-workplace research org the Upwork Research Institute,…


  • Progress fixes critical RCE flaw in Telerik Report Server, upgrade ASAP! (CVE-2024-6327)

    Progress fixes critical RCE flaw in Telerik Report Server, upgrade ASAP! (CVE-2024-6327) 2024-07-26 at 09:46 By Zeljka Zorz Progress Software has fixed a critical vulnerability (CVE-2024-6327) in its Telerik Report Server solution and is urging users to upgrade as soon as possible. About CVE-2024-6327 (and CVE-2024-6096) Telerik Report Server is an enterprise solution for storing,…


  • Ongoing Cyberattack Targets Exposed Selenium Grid Services for Crypto Mining

    Ongoing Cyberattack Targets Exposed Selenium Grid Services for Crypto Mining 2024-07-26 at 09:31 By Cybersecurity researchers are sounding the alarm over an ongoing campaign that’s leveraging internet-exposed Selenium Grid services for illicit cryptocurrency mining. Cloud security Wiz is tracking the activity under the name SeleniumGreed. The campaign, which is targeting older versions of Selenium (3.141.59…


  • CrowdStrike Warns of New Phishing Scam Targeting German Customers

    CrowdStrike Warns of New Phishing Scam Targeting German Customers 2024-07-26 at 09:31 By CrowdStrike is alerting about an unfamiliar threat actor attempting to capitalize on the Falcon Sensor update fiasco to distribute dubious installers targeting German customers as part of a highly targeted campaign. The cybersecurity company said it identified what it described as an…


  • UK and India sign broad tech collaboration pact

    UK and India sign broad tech collaboration pact 2024-07-26 at 09:01 By Laura Dobberstein Pick a hot market – AI, quantum, chips, 6G – and the pair have a plan to work on it together The UK and India agreed on Wednesday to a broad “Technology Security Initiative” that will see the two nations collaborate…


  • Omnissa, VMware’s old end-user biz, emerges with promise of ‘AI-infused autonomous workspace’

    Omnissa, VMware’s old end-user biz, emerges with promise of ‘AI-infused autonomous workspace’ 2024-07-26 at 08:32 By Simon Sharwood We think this means easier-to-administer virtual desktops with extra shiny Omnissa, the newly independent business created by Broadcom’s spinoff of VMWare’s end-user compute arm, has proclaimed it will become a source of “AI-infused autonomous workspaces”.… This article…


  • Critical Flaw in Telerik Report Server Poses Remote Code Execution Risk

    Critical Flaw in Telerik Report Server Poses Remote Code Execution Risk 2024-07-26 at 08:16 By Progress Software is urging users to update their Telerik Report Server instances following the discovery of a critical security flaw that could result in remote code execution. The vulnerability, tracked as CVE-2024-6327 (CVSS score: 9.9), impacts Report Server version 2024…


  • 16% of organizations experience disruptions due to insufficient AI maturity

    16% of organizations experience disruptions due to insufficient AI maturity 2024-07-26 at 07:31 By Help Net Security While sysadmins recognize AI’s potential, significant gaps in education, cautious organizational adoption, and insufficient AI maturity hinder widespread implementation, leading to mixed results and disruptions in 16% of organizations, according to Action1. Knowledge gap and training needs Sysadmins’…


  • AI-generated deepfake attacks force companies to reassess cybersecurity

    AI-generated deepfake attacks force companies to reassess cybersecurity 2024-07-26 at 07:31 By Help Net Security As AI-generated deepfake attacks and identity fraud become more prevalent, companies are developing response plans to address these threats, according to GetApp. In fact, 73% of US respondents report that their organization has developed a deepfake response plan. This concern…


  • One year after SEC cyber disclosure ruling, security leaders weigh in

    One year after SEC cyber disclosure ruling, security leaders weigh in 2024-07-26 at 07:16 By With a year in the rearview mirror, security professionals are reflecting on the SEC cyber disclosure ruling. This article is an excerpt from Subscribe to Security Magazine’s RSS Feed View Original Source React to this headline:


  • Most CISOs feel unprepared for new compliance regulations

    Most CISOs feel unprepared for new compliance regulations 2024-07-26 at 06:31 By Help Net Security With the new stringent regulations, including the SEC’s cybersecurity disclosure rules in the USA and the Digital Operational Resilience Act (DORA) in the EU, a significant challenge is emerging for many organizations, according to Onyxia Cyber. CISO role has changed…


  • North Korean chap charged for attacks on US hospitals, NASA – and even China

    North Korean chap charged for attacks on US hospitals, NASA – and even China 2024-07-26 at 06:01 By Simon Sharwood Microsoft, Mandiant, weigh in with info about methods used by Andariel gang alleged to have made many, many, heists The US Department of Justice on Thursday charged a North Korean national over a series of…


  • New infosec products of the week: July 26, 2024

    New infosec products of the week: July 26, 2024 2024-07-26 at 06:01 By Help Net Security Here’s a look at the most interesting products from the past week, featuring releases from GitGuardian, LOKKER, Permit.io, Secure Code Warrior, and Strata Identity. GitGuardian’s tool helps companies discover developer leaks on GitHub GitGuardian released a tool to help…


  • Malware crew Stargazers Goblin used 3,000 GitHub accounts to make bank

    Malware crew Stargazers Goblin used 3,000 GitHub accounts to make bank 2024-07-26 at 04:46 By Matthew Connatser May even have targeted other malware gangs, and infosec researchers Infosec researchers have discovered a network of over three thousand malicious GitHub accounts used to spread malware, targeting groups including gamers, malware researchers, and even other threat actors…


  • CrowdStrike update blunder may cost world billions – and insurance ain’t covering it all

    CrowdStrike update blunder may cost world billions – and insurance ain’t covering it all 2024-07-26 at 03:46 By Matthew Connatser We offer this formula instead: RND(100.0)*(10^9) The cost of CrowdStrike’s apocalyptic Falcon update that brought down millions of Windows computers last week may be in the billions of dollars, and insurance isn’t covering most of…


  • Sam Altman wants a US-led freedom coalition to fight authoritarian AI

    Sam Altman wants a US-led freedom coalition to fight authoritarian AI 2024-07-26 at 02:17 By Brandon Vigliarolo Team America AI Police? Sam Altman has called for a US-led coalition of nations to ensure AI remains a vehicle for freedom and democracy, and not a tool for authoritarians to keep themselves in power and dominate others. ……


  • Beware of fake CrowdStrike domains pumping out Lumma infostealing malware

    Beware of fake CrowdStrike domains pumping out Lumma infostealing malware 2024-07-26 at 01:46 By Jessica Lyons PSA: Only accept updates via official channels … ironically enough CrowdStrike is the latest lure being used to trick Windows users into downloading and running the notorious Lumma infostealing malware, according to the security shop’s threat intel team, which…


  • OpenAI unveils AI search engine SearchGPT – not that you’re allowed to use it yet

    OpenAI unveils AI search engine SearchGPT – not that you’re allowed to use it yet 2024-07-25 at 23:31 By Matthew Connatser Launching in Beta is so 2014. We’re in the pre-Beta limited sign-up era now After months of speculation, shy and retiring OpenAI has showed the world a glimpse of its very own web search…


  • FYI: Data from deleted GitHub repos may not actually be deleted

    FYI: Data from deleted GitHub repos may not actually be deleted 2024-07-25 at 23:01 By Thomas Claburn And the forking Microsoft-owned code warehouse doesn’t see this as much of a problem Researchers at Truffle Security have found, or arguably rediscovered, that data from deleted GitHub repositories (public or private) and from deleted copies (forks) of…


Browse older archives

Scroll to Top