Security News

Anatsa Android trojan now steals banking info from users in US, UK
2023-06-26 17:21

ThreatFabric discovered a previous Anatsa campaign on Google Play in November 2021, when the trojan was installed over 300,000 times by impersonating PDF scanners, QR code scanners, Adobe Illustrator apps, and fitness tracker apps. In March 2023, after a six-month hiatus in malware distribution, the threat actors launched a new malvertizing campaign that leads prospective victims to download Anatsa dropper apps from Google Play.

UK cyberspies warn ransomware crews targeting law firms
2023-06-23 12:09

British law practices of "All sizes and types" have been warned by GCHQ's cyberspy arm that their "Widespread adoption of hybrid working" combined with the large sums of money they handle is making them a target. Besides the mega cash transfers, the firms also often handle "Sensitive information," said the National Cyber Security Centre, making them "Particularly attractive targets to attackers."

UK telco watchdog Ofcom, Minnesota Dept of Ed named as latest MOVEit victims
2023-06-13 06:28

Two more organizations hit in the mass exploitation of the MOVEit file-transfer tool have been named - the Minnesota Department of Education in the US, and the UK's telco regulator Ofcom - just days after security researchers discovered additional flaws in Progress Software's buggy suite. Ofcom disclosed this week it is among the businesses and public bodies that have had their internal data stolen by crooks exploiting a MOVEit flaw.

Lantum S3 bucket leak is prescription for chaos for thousands of UK doctors
2023-06-12 12:34

A UK agency for freelance doctors has potentially exposed personal details relating to 3,200 individuals via unsecured S3 buckets, which one expert said could be used to launch ID theft attacks or blackmail. In the process, it discovered the Lantum S3 bucket, which was accessible and indexed on some IoT search engines.

UK government to set deadline for removal of Chinese surveillance cams
2023-06-08 07:30

The UK government will set a deadline for removing made-in-China surveillance cameras from "Sensitive sites." News of the not-very-imminent deadline came with on Tuesday with the publication of proposed amendments [PDF] to the Procurement Bill - legislation that will reform many aspects of the UK government's practices for buying stuff.

More UK councils caught by Capita's open AWS bucket blunder
2023-05-22 12:13

The bad news train keeps rolling for Capita, with more local British councils surfacing to say their data was put on the line by an unsecured AWS bucket, and, separately, pension clients warning of possible data theft in March's mega breach. Alison Parkin, director of financial services at Derby CC, said Capita supported its council tax and benefits service, and data left exposed was collected in early 2021.

UK's GDPR replacement could wipe out oversight of live facial recognition
2023-05-19 09:34

Biometrics and surveillance camera commissioner Professor Fraser Sampson has warned that oversight of facial recognition is a risk just as the policing minister plans to "Embed" it into the force. Sampson's job, if you were wondering, is to encourage "Compliance with the Surveillance Camera Code of Practice" - the only legal instrument that addresses police use of live facial recognition directly.

UK cops score legal win in EncroChat snooping op
2023-05-12 06:08

The UK's National Crime Agency has partially won an important legal battle in a case that challenged the warrants used to obtain messages from cyber crook hangout EncroChat. EncroChat offered an encrypted phone and mobile service for just $1,500 a month - and you thought your mobile bill was bad - which was chiefly used by criminals to organize their schemes and scams out of reach of the cops.

#UK
Users complain over UK state-owned bank's services as Atos eyes the exit
2023-05-05 08:30

The UK National Savings and Investment bank is being bombarded with complaints over failing online security and authentication features which customers say have locked them out of their accounts. The Register has contacted NS&I to offer it the opportunity to respond.

Survey: State of cybersecurity in the UK
2023-05-04 14:37

The survey is based on interviews conducted over the phone and online between September 27, 2022, and January 18, 2023, of 2,263 U.K. businesses, 1,174 U.K. registered charities and 554 education institutions. How are businesses identifying cybersecurity risks?