The Register - Anti-Virus

Syndikovat obsah
Biting the hand that feeds IT — Enterprise Technology News and Analysis
Aktualizace: 5 min 35 sek zpět

Malaysia is working on an internet 'kill switch', says minister

30 Červenec, 2024 - 04:29
Follows requirement for social media and messaging platforms to get a license

Legislation for an internet "kill switch" will reach Malaysia’s Parliament in October, according to the country's minister for Law and Institutional Reform.…

Kategorie: Viry a Červi

Meta's AI safety system defeated by the space bar

29 Červenec, 2024 - 23:01
'Ignore previous instructions' thwarts Prompt-Guard model if you just add some good ol' ASCII code 32

Meta's machine-learning model for detecting prompt injection attacks – special prompts to make neural networks behave inappropriately – is itself vulnerable to, you guessed it, prompt injection attacks.…

Kategorie: Viry a Červi

US border cops really must get a warrant in NY before searching your phones, devices

29 Červenec, 2024 - 22:17
Do we really want to bother SCOTUS with this, friends? Surely they're way too busy to take a look

US border agents must obtain a warrant, in New York at least, to search anyone's phone and other electronic device when traveling in or out of the country, another federal judge has ruled.…

Kategorie: Viry a Červi

Intruders at HealthEquity rifled through storage, stole 4.3M people's data

29 Červenec, 2024 - 15:45
No mention of malware or ransomware – somewhat of a rarity these days

HealthEquity, a US fintech firm for the healthcare sector, admits that a "data security event" it discovered at the end of June hit the data of a substantial 4.3 million individuals. Stolen details include addresses, telephone numbers and payment data.…

Kategorie: Viry a Červi

Google apologizes for breaking password manager for millions of Windows users with iffy Chrome update

29 Červenec, 2024 - 15:01
Happy Sysadmin Day

Google celebrated Sysadmin Day last week by apologizing for breaking its password manager for millions of Windows users – just as many Windows admins were still hard at work mitigating the impact of the faulty CrowdStrike update.…

Kategorie: Viry a Červi

Post-CrowdStrike, Microsoft to discourage use of kernel drivers by security tools

29 Červenec, 2024 - 08:30
Now there's an idea – parsing config data in user mode

Updated  Microsoft has vowed to reduce cybersecurity vendors' reliance on kernel-mode code, which was at the heart of the CrowdStrike super-snafu this month.…

Kategorie: Viry a Červi

China ponders creating a national 'cyberspace ID'

29 Červenec, 2024 - 07:28
Because clearly it's better for Beijing to know who you are than for every ISP and social service to keep its own records

Beijing may soon issue "cyberspace IDs" to its citizens, after floating a proposal for the scheme last Friday.…

Kategorie: Viry a Červi

Secure Boot useless on hundreds of PCs from major vendors after key leak

29 Červenec, 2024 - 03:58
Plus: More stalkerware exposure; a $16M TracFone fine; Ransomware victims don't use MFA, and more

Infosec in brief  Protecting computers' BIOS and the boot process is essential for modern security – but knowing it's important isn't the same as actually taking steps to do it.…

Kategorie: Viry a Červi

CrowdStrike meets Murphy's Law: Anything that can go wrong will

26 Červenec, 2024 - 20:36
And boy, did last Friday's Windows fiasco ever prove that yet again

Opinion  CrowdStrike's recent Windows debacle will surely earn a prominent place in the annals of epic tech failures. On July 19, the cybersecurity giant accomplished what legions of hackers could only dream of – bringing millions of Windows systems worldwide to their knees with a single botched update.…

Kategorie: Viry a Červi

Progress discloses second critical flaw in Telerik Report Server in as many months

26 Červenec, 2024 - 15:32
These are the kinds of bugs APTs thrive on, just ask the Feds

Progress Software's latest security advisory warns customers about the second critical vulnerability targeting its Telerik Report Server in as many months.…

Kategorie: Viry a Červi

North Korean chap charged for attacks on US hospitals, military, NASA – and even China

26 Červenec, 2024 - 04:58
Microsoft, Mandiant, weigh in with info about methods used by Andariel gang alleged to have made many, many, heists

The US Department of Justice on Thursday charged a North Korean national over a series of ransomware attacks on stateside hospitals and healthcare providers, US defense companies, NASA, and even a Chinese target.…

Kategorie: Viry a Červi

Malware crew Stargazers Goblin used 3,000 GitHub accounts to make bank

26 Červenec, 2024 - 03:34
May even have targeted other malware gangs, and infosec researchers

Infosec researchers have discovered a network of over three thousand malicious GitHub accounts used to spread malware, targeting groups including gamers, malware researchers, and even other threat actors who themselves seek to spread malware.…

Kategorie: Viry a Červi

CrowdStrike update blunder may cost world billions – and insurance ain't covering it all

26 Červenec, 2024 - 02:35
We offer this formula instead: RND(100.0)*(10^9)

The cost of CrowdStrike's apocalyptic Falcon update that brought down millions of Windows computers last week may be in the billions of dollars, and insurance isn't covering most of that.…

Kategorie: Viry a Červi

Beware of fake CrowdStrike domains pumping out Lumma infostealing malware

26 Červenec, 2024 - 00:30
PSA: Only accept updates via official channels ... ironically enough

CrowdStrike is the latest lure being used to trick Windows users into downloading and running the notorious Lumma infostealing malware, according to the security shop's threat intel team, which spotted the scam just days after the Falcon sensor update fiasco.…

Kategorie: Viry a Červi

FYI: Data from deleted GitHub repos may not actually be deleted

25 Červenec, 2024 - 21:51
And the forking Microsoft-owned code warehouse doesn't see this as much of a problem

Researchers at Truffle Security have found, or arguably rediscovered, that data from deleted GitHub repositories (public or private) and from deleted copies (forks) of repositories isn't necessarily deleted.…

Kategorie: Viry a Červi

Uncle Sam accuses telco IT pro of decade-long spying campaign for China

25 Červenec, 2024 - 19:15
Beijing has a long history of recruiting US residents to carry out various espionage activities

The US is looking to prosecute a Chinese immigrant over claims he has been drip-feeding information of interest to Beijing since at least 2012.…

Kategorie: Viry a Červi

You should probably fix this 5-year-old critical Docker vuln fairly sharpish

25 Červenec, 2024 - 15:46
For some unknown reason, initial patch was omitted from later versions

Docker is warning users to rev their Docker Engine into patch mode after it realized a near-maximum severity vulnerability had been sticking around for five years.…

Kategorie: Viry a Červi

Kaspersky says Uncle Sam snubbed proposal to open up its code for third-party review

25 Červenec, 2024 - 14:01
Those national security threat claims? 'No evidence,' VP tells The Reg

Exclusive  Despite the Feds' determination to ban Kaspersky's security software in the US, the Russian business continues to push its proposal to open up its data and products to independent third-party review – and prove to Uncle Sam that its code hasn't been and won't be compromised by Kremlin spies.…

Kategorie: Viry a Červi

Patch management still seemingly abysmal because no one wants the job

25 Červenec, 2024 - 09:27
Are your security and ops teams fighting to pass the buck?

Comment  Patching: The bane of every IT professional's existence. It's a thankless, laborious job that no one wants to do, goes unappreciated when it interrupts work, and yet it's more critical than ever in this modern threat landscape.…

Kategorie: Viry a Červi

How a cheap barcode scanner helped fix CrowdStrike'd Windows PCs in a flash

25 Červenec, 2024 - 04:29
This one weird trick saved countless hours and stress – no, really

Not long after Windows PCs and servers at the Australian limb of audit and tax advisory Grant Thornton started BSODing last Friday, senior systems engineer Rob Woltz remembered a small but important fact: When PCs boot, they consider barcode scanners no differently to keyboards.…

Kategorie: Viry a Červi