Security News

Before you go away for Xmas: You've patched that critical Perforce Server hole, right?
2023-12-19 19:57

Four vulnerabilities in Perforce Helix Core Server, including one critical remote code execution bug, should be patched "Immediately," according to Microsoft, which spotted the flaws and disclosed them to the software vendor. Redmond's flaw finders reported the security holes in late August, and Perforce patched them in November, we're told, so hopefully you've already updated your installations and can relax.

FBI: ALPHV ransomware raked in $300 million from over 1,000 victims
2023-12-19 19:32

The ALPHV/BlackCat ransomware gang has made over $300 million in ransom payments from more than 1,000 victims worldwide as of September 2023, according to the Federal Bureau of Investigation. "ALPHV Blackcat affiliates have extensive networks and experience with ransomware and data extortion operations," the FBI says.

Interpol operation arrests 3,500 cybercriminals, seizes $300 million
2023-12-19 19:09

An international law enforcement operation codenamed 'Operation HAECHI IV' has led to the arrest of 3,500 suspects of various lower-tier cybercrimes and seized $300 million in illicit proceeds. 199 million of the seized amounts concern hard currency, and the remaining $101 million corresponds to the value of 367 digital/virtual assets, such as NFTs linked to cybercrime.

Microsoft confirms Windows 11 Wi-Fi issues, asks for user feedback
2023-12-19 18:40

Microsoft has confirmed that some Windows 11 devices experience Wi-Fi connectivity issues after installing recent cumulative updates. "Microsoft has received reports of an issue in which some Wi-Fi adapters might not connect to some networks after installing KB5032288," Redmond said in a new update to the Windows release health hub.

How the FBI seized BlackCat (ALPHV) ransomware’s servers
2023-12-19 17:27

An unsealed FBI search warrant revealed how law enforcement hijacked the ALPHV/BlackCat ransomware operations websites and seized the associated URLs. "As a result, the FBI identified and collected 946 public/private key pairs for Tor sites that the Blackcat Ransomware Group used to host victim communication sites, leak sites, and affiliate panels like the ones described above."

Terrapin attacks can downgrade security of OpenSSH connections
2023-12-19 17:03

This manipulation lets attackers remove or modify messages exchanged through the communication channel, which leads to downgrading the public key algorithms used for user authentication or disabling defenses against keystroke timing attacks in OpenSSH 9.5. "The Terrapin attack exploits weaknesses in the SSH transport layer protocol in combination with newer cryptographic algorithms and encryption modes introduced by OpenSSH over 10 years ago."

What Australia’s Digital ID Means to How Citizens Interact With Businesses Online
2023-12-19 16:40

Australia is about to get a national online ID system - the Digital ID - which promises to improve the security and privacy of data online. The Digital ID is the cumulation of a five-year, AUD $200 million investment as an effort to alleviate security concerns over the amount of data Australians give to companies to prove who they are online.

12 Essential Steps Mac Users Need To Take At Year End
2023-12-19 16:16

As the year comes to a close, Mac users should take these steps to ensure their device's security, performance and organization. Here are the year-end steps you should take to ensure your Mac is ready for 2024.

Law enforcement seizes ALPHV/Blackcat sites, offers decryptor to victims
2023-12-19 16:03

The US Justice Department announced today a disruption campaign against the Blackcat/ALPHV ransomware group and let victims know that there is a decryptor they can use. Over the past 18 months, ALPHV/Blackcat has emerged as the second most prolific ransomware-as-a-service variant in the world based on the hundreds of millions of dollars in ransoms paid by victims around the world.

FBI Takes Down BlackCat Ransomware, Releases Free Decryption Tool
2023-12-19 15:52

The U.S. Justice Department (DoJ) has officially announced the disruption of the BlackCat ransomware operation and released a decryption tool that victims can use to regain access to files locked...