Security Russians are posing as Signal support to launch phishing attacks PLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more!
Security Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attack PLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more
Black Hat and DEF CON DEF CON Franklin project enlists hackers to harden critical infrastructure Voting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included
Security EQT buys majority share in Swiss cybersecurity biz Acronis Went at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified
Malware Month Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sight On the plus side, infosec's a good bet for a long, stable career
Security India's CERT given exemption from Right To Information requests Activists worry investigations may stay secret, and then there's those odd incident reporting requirements
Research Ransomware attacks register record speeds thanks to success of infosec industry Dwell times drop to hours rather than days for the first time
Security CISA reveals 'Admin123' as top security threat in cyber sloppiness chart Calls for wider adoption of security-by-design principles continue to ring loudly from Uncle Sam
Security Japan drives for infosec self-sufficiency – at least in one layer of deep defenses CYNEX Alliance brings industry, government, and academia together to share info and devise tools
Cyber-crime Recycling giant TOMRA pulls systems offline following 'extensive cyberattack' Says baddies launched attack at weekend, isolates parts of tech infrastructure to contain spread
CSO NASA infosec again falls short of required US government standard Good thing space agency doesn’t have any state secrets … oh, hang on
Patches Fortinet warns of critical flaw in its security appliance OSes, admin panels Naturally, they're already under attack – so you know what to do next
On-Prem Inflation, recession, pah! IT budgets set to rise in 2023 Turns out all it took was a business-disrupting global pandemic
Security Russia, Iran discuss tech manufacturing, infosec and e-governance collaboration Proposed working group would see Moscow's miltech conglomerate Rostec operate in Tehran
Security Indian government issues confidential infosec guidance to staff – who leak it Bans VPNs, Dropbox, and more
Security Emma Sleep Company admits checkout cyber attack Customers wake to a nightmare as payment data pilfered from UK website
Security Russia is the advanced persistent threat that just triggered. Ready? Data security looks very different when your life depends on it
Security Cyberattacker hits German service station petrol terminal provider Shell station logistics supplier Oiltanking 'operating with limited capacity'
Security UK government opens consultation on medic-style register for Brit infosec pros Are you competent? Ethical? Welcome to UKCSC's new list
Security EU needs more cybersecurity graduates, says ENISA infosec agency – pointing at growing list of master's degree courses Skills gap needs filling somehow
Security Turbine maker Vestas Wind Systems admits to cyber incident, refuses to confirm if ransomware is at play Company data compromised but not systems containing customer or supplier information
Security Patch now? Why enterprise exploits are still partying like it's 1999 Am I only dreaming, or is this burning an Eternal Blue?
Security Northern Train's ticketing system out to lunch as ransomware attack shuts down servers £17m on shiny new Flowbird touchscreen kiosks well spent, apparently
Security Military infosec SNAFUs: What WhatsApp and bears in the woods can teach us One can’t spell shit without IT, but for Pete's sake it doesn't need to be in your endpoints
Security Good news for pentesters and network admins: US issues ransomware guidance asking biz to skill up security teams New approach against malware pushers mirrors how American authorities handle terrorism cases
Security The policy of truth: As ransomware claims rise, what's a cyber insurer to do? Never again is what you swore... the time before
Security Brit retailer Furniture Village confirms 'cyber-attack' as systems outage rolls into Day 7 Sofa, not-so-good: Angry customers still can't access systems, phones, and deliveries delayed
Security Computer Misuse Act: Tell the Home Office infosec needs a public interest defence in law, says CyberUp campaign Bug-hunting industry wants to know a bit more before doing that, though
Security Ethics isn't a county east of London, but it's the only way to look at security We are all human beings, we live in a community, and everything we do affects others
Security Money can buy you insurance against network break-ins but investing in infosec hygiene wouldn't go amiss, says new NCSC chief C-suites need a kick up the proverbial, says Lindy Cameron in first speech
Security Smart doorbells on business premises make your property more attractive to burglars, warns researcher Spend your cash on real locks, advises Cranfield University
Security Å nei! Norway's Stortinget struck by Microsoft Exchange malware 'Data has been extracted' as Swiss-cheese servers are exploited
Security Oh SITA: Airline IT provider confirms passenger data leaked after major 'cyber-attack' Data from multiple aviation giants hit
Devops SitePoint hacked: Hashed, salted passwords pinched from web dev learning site via GitHub tool pwnage If you started off there, best change your reused credentials
Security Today's 'sophisticated cyber attack' victim is the Woodland Trust: Pre-Xmas breach under investigation Potentially 250,000 reasons UK nature conservation charity was targeted
Security Digital burglars break into the Australian Securities and Investments Commission Miscreant fingered server that held docs related to credit applications down under
Security Will there be no end to govt attempts to break encryption? Hand over your data or the kiddies get it, threaten Five Eyes spies The Great Unicorn Prayer of security services: Stay secure, but - ya know - give us backdoors
Security COVID-19 security tips: Ensure you sack your staff without leaving their IT access enabled, says Secureworks Infosec biz issues mildly off-the-wall guidance for incident responders
Security Hackers hack Hackney: Local government cries 'cyberattack' while UK infosec officials rush to figure out what happened Check bank accounts, don't open council emails, you know how this goes
Software Your anti-phishing test emails may be too easy to spot. NIST has a training tool for that Phish Scale hopes to make life easier for blue teams gazing at click rates
Security Where China leads, Iran follows: US warns of 'contract' hackers exploiting Citrix, Pulse Secure and F5 VPNs Please just patch your infrastructure, begs US-CISA
Security Don't pay the ransom, mate. Don't even fix a price, say Australia's cyber security bods Better yet - do the basics and your systems won't get encrypted in the first place
Security Warehouse management software biz SnapFulfil hit by ransomware: It's not just the big dogs getting KO'd I get knocked down, but I get up again... eventually
Security CREST: We are investigating NCC Group certification cheat sheet scandal – and not with NCC personnel Infosec cert body looking into it as under-fire firm starts its own probe
Security UK's NCSC reveals Premier League footie clubs to be ripe pickings for cybercrooks: One almost lost £1m to BEC attack Switch on, urges GCHQ-backed public security agency
Security Burn baby burn, infosec inferno: Just 21% of security pros haven't considered quitting their current job Chartered Institute of Information Security finds many overworked, under-resourced, stressed
Security Criminals auction off stolen domain admin credentials for up to £95k. Your bank account details? Barely get £50 Dark web dwellers can pick and choose from billions - billions - of logins
Databases No Wiggle room: Two weeks after angry bike shop customers report mystery orders on their accounts, firm confirms payment cards delinked It was a fraudster! Finally an excuse for why there's a £250 Lycra bodysuit on your bank statement
Security Have I Been Pwned breach report email pwned entire firm's helldesk ticket system That's one way of making people check for updates
Security More Salt in their wounds: DigiCert hit as hackers wriggle through (patched) holes in buggy config tool Miscreants too busy mining for crypto to notice the gold lying around them?
Security AsSalt-ed at the weekend: Miscreants roast Ghost, LineageOS totters as Salt bug bites Ah oh, SaltStack's frightnin' (with apologies to Howlin' Wolf)
Security Xiaomi emits phone browser updates after almighty row over web activity harvested even in incognito mode Plus: Other infosec news from around the internet
Edge + IoT Tech tracker Tile testifies in Congress: Apple's geolocation nagging is so not fair Alleges anticompetitive behaviour in the walled garden. There's no party like a third party, eh?
SaaS Access Analysis, GuardDuty and Inspector gadgets not enough? Here comes another AI-driven security tool for AWS What have you got for us, Detective?
Security Got your number? Maybe. 118 118 Money shutters website after spotting an intruder No word on what digi burglars lifted
Security UK data watchdog slaps a £500,000 fine on Cathay Pacific for 2018 9.4m customer data leak ICO probe found backup files not password-protected, unpatched web-facing servers, out-of-date OS and more
Security Beware of bad Santas this Xmas: Piles of insecure smart toys fill retailers' shelves Latest Which? study with NCC Group highlights toys it ain't smart to buy
Security In a world of infosec rockstars, shutting down sexual harassment is hard work for victims How a close-knit hero-worshiping culture can make reporting abusers difficult – and how help is at hand
Legal UK culture sec hints at replacing TV licence fee, defends encryption ban proposals and her boss in Hacker House inquiry Nuggets from Nicky Morgan's grilling by select committee
Security Fed-up graphic design outfit dangles cash to anyone who can free infosec of hoodie pics Make stock images great again!
Security Driving Xtreme Cuts: DXC Technology waves bye bye to 45% of Americas Security divison 50 roles shifted off to India
Security Strewth: Hackers slurp 19 years of Oz student data in uni's second breach within a year Upgraded its systems after attack in early '18, just enough to detect attack in late '18
Security Pharma-testing biz Eurofins Scientific says it fell victim to 'new version' of malware No data nicked in weekend attack but systems and server pulled to contain infection
Security Go on, Skippy, spill yer guts: 10.5 million+ Australians' data was breached in past 3 months Out of 25 million? Cripes
Security Brit events and info biz Incisive Media admits open server port may have left readers deets exposed Home of CRN UK, Computing and others warn remaining readers to update their freakin' passwords
Security There's NordVPN odd about this, right? Infosec types concerned over strange app traffic Firm explains but security folk not appy with clarifications
Security Old-school cruel: Dodgy PDF email attachments enjoying a renaissance Let's go back... way back
Security Hackers bragged that pretty vanilla breach included FBI watchlist? Well, colour us shocked It didn't, by the way – it's a bunch of ad industry folk
OSes Patch blues-day: Microsoft yanks code after some PCs are rendered super secure (and unbootable) following update Sophos, Avast users left wailing as update borks older OSes
Security You don't need a PhD to phish a Brit university: Nonprofit claims 100% hit rate is easy peasy And if it ain't that, it's hacked-off students firing out DDoSes
Security New phisherman's friends and a few old favourites slither out of WatchGuard's Security Report New entry in network attack hit parade: That 2017 Cisco WebEx flaw you patched already (right?)
Security Reg webinar: Tune in for some knowledge on how to become an effective leader in IT security The benefits of pragmatism
Security NASA's crap infosec could be 'significant threat' to space ops Inspectors not happy with stagnant security practices
Security Armor Games admits all its users' deets slurped in database mega-hack as site moves to repair chink We were caught in hack that bled 617 million online accounts
Security Accused hacker Lauri Love loses legal bid to reclaim seized IT gear Spared court costs as he reveals £120-a-week income
Security Revealed: Numbers show extent of security fears about security biz Kaspersky Lab Global sales up 4% but North America element down 25%
Security Trakt app users' personal data exposed: We were hit by a 'PHP exploit'... back in 2014 No payment info, but users' names, locations, email addies etc all 'lost'
Legal Diplomat warns that tech industry has become a pawn as politicos fight dirty They see AI, cybersecurity as 'battle fronts' - and rising populism will make it worse - former UN official
Security Between you, me and that dodgy-looking USB: A little bit of paranoia never hurt anyone Let's lift our eyes from the balance sheet and take a look around...
Security We can rebuild him, we have the technology: AI will help security teams smack pesky anomalies Big data, smart machines and analytics, with a human behind the wheel
Security Trump wants to work with Russia on infosec. Security experts: lol no Thanks for Putin that out there
Security UK Minister of Fun Matt Hancock opens London infosec upstart creche £13m thing aims to get newbies playing with the big boys
Security Deck the halls with HALs: AI steals the show at Infosec Europe A welcome break from GDPR and blockchain
Security WannaCry reverse-engineer Marcus Hutchins hit with fresh charges Accused of creating UPAS Kit and lying to FBI
Security Just a third of Brit cops are equipped to fight crime that is 'cyber' Bad news if you've been defrauded online
Security Have you heard about ransomware? Now's the time to ask: Are you covered? Cyber-insurance gig to be worth $14bn by 2022
Legal Oz military megahack: When crappy defence contractor cybersecurity 'isn't uncommon', surely alarm bells ring? 30GB of data nicked in 'Alf's Mystery Happy Fun Time' attack
Networks Welcome to the Rise of the Machine-to-Machine. Isn't it time to 'block off' some data ducts? Isolation-based security is getting important
Security Australia' Smart meter leaders lag in securing devices Centre for Internet Safety calls for consumer safeguards
Security Speaking in Tech: A chat with Web 2.0 MySpace worm dude Samy Kamkar Gang discuss PoisonTap, SHA-1 and get a how-to on hacking
On-Prem FireEye execs exit, following hundreds of staff restructured into redundancy Board chair and CFO resign