| /// |
|
| Headlines : Theregister Sec News | Page 1 |
|
Security boffins scoured the web and found hundreds of valid API keys - 27/03 3:04 pm Global bank's devs have some cleaning up to do after cloud creds found in website code Computer security boffins have conducted an analysis of 10 million websites and found almost 2,000 API credentials strewn across 10,000 webpages. |
|
Brit lawmaker targeted by AI deepfake fails to get answers from US Big Tech - 26/03 7:49 pm Appearing before Parliament, Meta, Google and X struggle to explain how fake political video circulated for so long A member of the UK Parliament's lower house who was the victim of a deepfake AI campaign this week had a rare chance to confront the Big Tech executives who helped spread it. Their answers disappointed. |
|
UK wants to know if banning under-16s from social media does anything .. - 26/03 5:30 pm 300 families undergo 6-week trial to test impact on sleep, school, and home life The UK government will trial different levels of restrictions on social media for under-16s with the help of 300 families, alongside a public consultation that has already gathered nearly 30,000 responses. |
|
Indian government probes CCTV espionage operation linked to Pakistan - 26/03 11:18 am Police found cameras pointing at infrastructure Indian authorities have reportedly ordered an audit of the nations CCTV cameras, after police uncovered what they claim was a Pakistan-backed surveillance operation. |
|
AI supply chain attacks dont even require malwarejust post poisoned .. - 26/03 4:52 am A proof-of-concept attack on Context Hub suggests there's not much content santization A new service that helps coding agents stay up to date on their API calls could be dialing in a massive supply chain vulnerability. |
|
Scammers have virtual smartphones on speed dial for fraud - 26/03 4:25 am They cleverly mimic most traits of a real phone Smartphones have fast become the basis of our digital identities, securing payment systems and bank accounts. Now virtual devices that pretend to be real handsets have become a key tool for financial scammers, according to one company. |
|
Jen Easterly, cybersecurity's 'relentless optimist,' hopes feds come back .. - 26/03 3:39 am Ex-CISA boss also says no reason to panic about AI and security RSAC 2026 "Everybody feels massive FOMO if they don't get to RSAC," Jen Easterly says. |
|
Only Trump can decide when cyberwar turns into real war - 26/03 2:55 am Four former NSA bosses walk onto the stage at RSAC rsac 2026 There's a theoretical red line with cyber warfare. Cross it, and the US will respond with a physical attack like missile strikes. And that line "is whatever the President says it is," according to former NSA boss retired General Paul Nakasone. |
|
Enterprise PCs are unreliable, unpatched, and unloved compared to Macs - 25/03 3:29 pm Omnissa telemetry suggests business buyers are loving Apple and Google End- user compute vendor Omnissa, the company formed by the spin-out of VMwares virtual desktops, applications, and device management biz, has dug into the telemetry it collects from customers and painted a picture of the worlds enterprise hardware fleet and the news is better for Google and Apple than it is for Microsoft. |
|
EFF has a new boss to lead the fight against privacy-sucking forces of doom - 25/03 6:44 am Cyber rights org retools for the days of AI and unrestrained government interview The Electronic Frontier Foundation (EFF) on Tuesday appointed Nicole Ozer to succeed Cindy Cohn as the cyber rights group's executive director when Cohn departs this summer. |
|
1K+ cloud environments infected following Trivy supply chain attack - 25/03 4:31 am Crims 'creating a snowball effect' across open source projects RSAC 2026 Thousands of organizations' cloud environments have been infected with secret- stealing malware as a result of the Trivy supply-chain attack last week, and now the crims that compromised the open source scanners are working with notorious extortion crews like Lapsus$. |
|
LiteLLM loses game of Trivy pursuit, gets compromised - 25/03 3:11 am Python interface for LLMs infected with malware via polluted CI/CD pipeline Two versions of LiteLLM, an open source interface for accessing multiple large language models, have been removed from the Python Package Index (PyPI) following a supply chain attack that injected them with malicious credential- stealing code. |
|
Country that put backdoors into Cisco routers to spy on world bans foreign .. - 24/03 9:48 pm Unfortunately, there aren't many options unless you're Starlink Citing national security fears, America is effectively banning any new consumer-grade network routers made abroad. |
|
HackerOne slams supplier for delayed breach notice after staff data exposed - 24/03 9:27 pm Nearly 300 employees caught up in intrusion at benefits provider Navia Almost 300 HackerOne employees are caught up in a data breach, with the bug bounty biz slamming a third-party benefits provider for a weeks-long delay in notification. |
|
Russian initial access broker who fed ransomware crews gets 81 months in .. - 24/03 7:32 pm Aleksei Volkov sentenced after enabling attacks that cost victims millions A Russian national who sold the keys to corporate networks faces nearly seven years in a US prison after prosecutors tied his handiwork to a string of ransomware attacks costing victims millions of dollars. |
|
Claude attacks were 'Rorschach test' for infosec community, scaring former .. - 24/03 6:50 am 'It freakin' worked' says Rob Joyce - and shows how relentless AI agents can find holes humans miss RSAC 2026 The now-infamous Anthropic report about Chinese cyberspies abusing Claude AI to automate cyberattacks was a Rorschach test for the infosec community, according to former NSA cyber boss Rob Joyce. |
|
Public-private partnerships vital in disrupting China's Typhoons, says RSA .. - 24/03 6:46 am Washington content to be represented by actual empty chairs RSAC 2026 Back in the day (circa 2023) when cybercrime group Scattered Spider and its help-desk voice-phishing calls were a relatively new threat, the feds considered pulling the government's top cyber-threat hunters and their private-sector counterparts into one room to share information, in real time, about this loosely knit extortion ring that was terrorizing enterprises. |
|
Smooth criminals talking their way into cloud environments, Google says - 24/03 6:45 am Voice phishing is second most common initial access method across all IR probes, and top in cloud break-ins RSAC 2026 Voice phishing surged last year to become the second most common method used by cybercriminals to gain initial access to their victims' IT estate and the No. 1 tactic used when breaking into cloud environments. |
|
Lightning-fast exploits make it essential to patch fast, ask questions .. - 24/03 4:42 am Here's where you ought to spend your security billable hours budget this year Strengthen your MFA policies, double-down on anti-phishing training, and for Jobs' sake, patch all your vulns right away. The past year of intelligence collected by Cisco's Talos threat hunters suggests that attackers are moving faster to exploit vulns, and fooling more staff than ever into giving up their credentials. |
|
US chip testing firm shrugged off ransomware hit as minor then came the .. - 24/03 12:47 am Trio-Tech International initially said hack wasn't 'material,' but then stolen data was published Trio-Tech International initially shrugged off a ransomware attack at a Singapore subsidiary as immaterial, only to reverse course days later after discovering stolen data had been disclosed. |
|
Google unleashes Gemini AI agents on the dark web - 23/03 11:05 pm Claims it can analyze millions of daily events with 98 percent accuracy Google's Gemini AI agents are crawling the dark web, sifting through upward of 10 million posts a day to find a handful of threats relevant to a particular organization. |
|
RSAC 2026: Uncle Sam backs out, and AI agents are everywhere - 23/03 8:24 pm Infosec pros descend on San Francisco kettle When El Reg cybersecurity editor Jessica Lyons joins infosec industry colleagues in San Francisco for RSAC 2026 this week, she's expecting agentic AI to be on everyone's lips - at least those who aren't busy gossiping about the lack of presence from any representatives of the US federal government. |
|
Microsoft fixes broken Windows update days after vowing fewer broken .. - 23/03 7:24 pm The era of reliability begins... right after this out-of-band patch Microsoft has released an out-of-band update to resolve bugs introduced by a Windows patch just days after promising improved reliability. |
|
The drone swarm is coming, and NATO air defenses are too expensive to cope - 23/03 6:14 pm Ukraine's battlefield lessons show quantity and affordability now trump exquisite hardware NATO is unprepared to deal with attacks by cheap, mass- produced drones and urgently needs layered, affordable air defense systems to counter the threat, taking a cue from the experience gained by Ukrainian forces over the past four years. |
|
Russians are posing as Signal support to launch phishing attacks - 23/03 7:22 am PLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more! Infosec In Brief Russian intelligence- affiliated parties are posing as customer support services on commercial messaging applications such as Signal to compromise accounts and conduct phishing attacks, the FBI and Cybersecurity and Infrastructure Security Agency (CISA) warned last Friday. |
|
Cryptographers engage in war of words over RustSec bug reports and .. - 21/03 6:19 am Rust security maintainers contend Nadim Kobeissi's vulnerability claims are too much Since February, cryptographer Nadim Kobeissi has been trying to get code fixes applied to Rust cryptography libraries to address what he says are critical bugs. For his efforts, he's been dismissed, ignored, and banned from Rust security channels. |
|
UK police force presses pause on live facial recognition after study finds .. - 20/03 9:35 pm Cams statistically more likely to ID Black people, says new research A UK police force has suspended its deployment of live facial recognition (LFR) technology after a study revealed it was statistically more likely to identify Black people on a watchlist database. |
|
Feds disrupt monster IoT botnets behind record-breaking DDoS attacks - 20/03 9:07 pm Millions of hijacked devices powered traffic floods targeting defense systems and beyond The US government has moved to disrupt a cluster of IoT botnets behind some of the largest DDoS attacks ever recorded, including traffic bursts topping 30 terabits per second. |
|
Jaguar Land Rover's cyber bailout sets worrying precedent, watchdog warns - 20/03 8:42 pm Lack of clear criteria risks encouraging firms to lean on state support instead of worrying about insurance The UK's cyber watchdog has warned that the government's 1.5 billion bailout of Jaguar Land Rover (JLR) risks setting a troubling precedent for how Britain handles major cyber crises. |
|
Starmer's digital ID reboot raises same old questions as its Blair-era .. - 20/03 6:15 pm Audit trails aplenty, but no price tag and no clue how long your data sticks around Opinion Last week's UK government consultation on its plans for digital identity had quite a few things missing. It did not include a price estimate - something it said was due to decisions yet to be taken on the scheme's scope - or how long the government would keep "audit trail" records of ID checks. |
|
While you're here, could you go out of your way to do an impossible job? - 20/03 3:30 pm He would have gotten away with it too, if it weren't for a meddling security team's fear of USB On Call Each Friday The Register offers a fresh installment of On Call, the reader-contributed column that celebrates the fine art of tech support. |
|
Unknown attackers exploit yet another critical SharePoint bug - 20/03 2:54 am Last time: Beijing-backed snoops and ransomware crims. Who's next? Unknown baddies are abusing yet another critical Microsoft SharePoint bug to compromise victims' SharePoint servers, the US government warned. |
|
Google gives Android users a way to install unverified apps if they prove .. - 20/03 2:30 am Chocolate Factory describes concession as an attempt to balance openess with safety It turns out you won't be limited to Google-verified apps an developers on Android after all. In the face of sustained community dissatisfaction with its developer verification requirement, Google has given Android users an out. |
|
Lock down Microsoft Intune, feds warn after Stryker attack - 20/03 12:00 am Iran-linked attackers wiped employees' devices using Intune The US government has urged companies to better secure Microsoft Intune, an endpoint management tool that was abused in last week's cyberattack against med-tech firm Stryker. |
|
Okta made a nightmare micromanager for your AI agents - 19/03 7:05 am Where are you? What are you working on? Why are you doing that? Identity access and management platform Okta announced the general availability of its Okta for AI Agents, which will give customers the ability to do three things: locate agents, see what theyre doing, and shut them down if need be. |
|
State snoops and spyware vendors planting info-stealing malware on .. - 19/03 5:39 am Darksword is the second iOS exploit chain in a month A new exploit kit targeting iPhone users and stealing their sensitive data is being abused by "multiple" spyware vendors and suspected nation-state goons, security researchers said on Wednesday. |
|
Amazon security boss says crims abused max-security Cisco firewall flaw .. - 19/03 1:40 am Interlock's post-exploit toolkit exposed Ransomware criminals exploited CVE-2026-20131, a maximum-severity bug in Cisco Secure Firewall Management Center software, as a zero-day vulnerability more than a month before Cisco patched the hole, according to Amazon security boss CJ Moses. |
|
North Korea's 100,000-strong fake IT worker army rake in $500M a year for .. - 18/03 9:57 pm Researchers map full org chart of the scam from dodgy recruiters to helpful Western collaborators Researchers at IBM XForce and Flare Research have uncovered data that sheds light on how North Korea's fake IT worker schemes operate and infiltrate companies in order to funnel money back to the regime and steal sensitive information. |
|
Britain's satellite-watching gap to be plugged with 17.5M eyeball in Cyprus - 18/03 8:35 pm No 1 Space Operations Squadron will get a persistent stare capability The Ministry of Defence (MoD) plans to spend 17.5 million on a remotely-operated satellite monitoring facility in Cyprus, partly to protect the UK's secure communications system Skynet. |
|
Iran's cyberattack against med tech firm is 'just the beginning' - 18/03 3:32 pm Even without a navy, or air power, 'They'll still have the ability to hack' Businesses should expect that Iran will conduct more aggressive cyber-ops as the war escalates, according to security analysts. |
| Reformasi | >> |
| Kroni | >> |
| Tabloid | >> |
| Tech | >> |
| World | >> |
| Motor Trend | >> |