Security News

UK and allies expose Russian FSB hacking group, sanction members
2023-12-07 16:38

The UK National Cyber Security Centre and Microsoft warn that the Russian state-backed actor "Callisto Group" is targeting organizations worldwide with spear-phishing campaigns used to steal account credentials and data. Today, the United Kingdom officially attributed attacks to Callisto that led to the leaking of UK-US trade documents, the 2018 hack of the UK think tank Institute for Statecraft, and more recently, the hack on StateCraft's founder Christopher Donnelly.

Yet another UK public sector data blab, this time info of pregnant women, cancer patients
2023-12-07 12:39

In both cases, it was an own goal when the org handed over the data itself while responding to requests made under the Freedom of Information Act 2000. The majority of the patients whose data was made public were maternity patients of The Rosie Hospital at the Addenbrooke's Hospital site.

#UK
Australia building 'top secret' cloud to catch up and link with US, UK intel orgs
2023-12-07 04:33

Australia is building a top-secret cloud to host intelligence data and share it with the US and UK, which have their own clouds built for the same purpose. The three clouds were discussed on Monday by Andrew Shearer, Australia's director-general of national intelligence, at an event hosted by the Center for Strategic & International Studies in Washington, DC. "We are working very hard on a top-secret cloud initiative," Shearer told the event, adding that it will interoperate with similar infrastructure already operated by the US and UK, and mean sensitive data can be shared "Near instantaneously."

It's ba-ack... UK watchdog publishes age verification proposals
2023-12-05 10:22

Digital identity wallets and, our favorite, facial age estimation, where the features of a user's face are analyzed to estimate the user's age. The idea of age verification was floated years before and has returned as part of the Online Safety Bill.

#UK
UK government denies China/Russia nuke plant hack claim
2023-12-05 06:30

The government of the United Kingdom has issued a strongly worded denial of a report that the Sellafield nuclear complex has been compromised by malware for years. The report, appearing in The Guardian, claimed that the controversial complex was hacked by "Cyber groups closely linked to Russia and China," with the infection detected in 2015 but perhaps present before that year.

UK government rings the death knell for SIM farms
2023-11-29 11:01

The UK government plans to introduce new legislation to ban SIM farms, which it views as a widely abused means for carrying out cyber fraud. SIM farms are defined as devices that can hold four or more SIM cards while having the ability to make phone calls and send texts.

UK and South Korea: Hackers use zero-day in supply-chain attack
2023-11-24 17:28

The attack started with compromising a media outlet's website to embed malicious scripts into an article, allowing for a 'watering hole' attack. State-backed North Korean hacking operations consistently rely on supply chain attacks and the exploitation of zero-day vulnerabilities as part of their cyber warfare tactics.

Cyberattack on IT provider CTS impacts dozens of UK law firms
2023-11-24 17:13

A cyberattack on CTS, a leading managed service provider for law firms and other organizations in the UK legal sector, is behind a major outage impacting numerous law firms and home buyers in the country since Wednesday. "We are experiencing a service outage which has impacted a portion of the services we deliver to some of our clients. The outage was caused by a cyber-incident," the UK IT services provider said in a statement published on Friday.

UK's cookie crumble: Data watchdog serves up tougher recipe for consent banners
2023-11-22 10:15

The UK's Information Commissioner's Office is getting tough on website design, insisting that opting out of cookies must be as simple as opting in. At question are advertising cookies, where users should be able to "Accept All" advertising cookies or reject them.

#UK
Samsung UK discloses year-long breach, leaked customer data
2023-11-17 05:58

The UK division of Samsung Electronics has allegedly alerted customers of a year-long data breach - the third such incident the South Korean giant has experienced around the world in the past two years. An email to customers, shared on social media by web security consultant and Have I Been Pwned creator Troy Hunt, detailed that the breach exposing data of customers who made purchases between July 1, 2019 and June 30, 2020 was discovered on November 13.