| /// |
|
| Headlines : Theregister Sec News | Page 1 |
|
Firefox taps Anthropic AI bug hunter, but rancid RAM still flipping bits - 7/03 4:41 am Now if only device makers would deliver higher quality components Thanks to Anthropic's AI and its bug-detecting abilities, Firefox users can now enjoy stronger security. Unfortunately, if browser crashes rather than security flaws are the problem, Claude probably can't help. |
|
Spyware disguised as emergency-alert app sent to Israeli smartphones - 7/03 2:56 am Steals SMS messages, location data, contacts and delivers it to Hamas-linked crew Hamas-linked attackers are dropping spyware disguised as an emergency- alert app on Israelis' smartphones via SMS messages, according to security researchers. |
|
Cisco warns of two more SD-WAN bugs under active attack - 6/03 11:04 pm Switchzilla says flaws could allow file overwrites or privilege escalation Just when network admins thought the Cisco SD-WAN patch queue might finally be shrinking, Switchzilla has confirmed miscreants are exploiting more vulnerabilities in its SD-WAN management software. |
|
Microsoft spots ClickFix campaign getting users to self-pwn on Windows .. - 6/03 9:37 pm Crooks tweak familiar copy-paste ruse so that victims run malicious commands themselves A new twist on the long-running ClickFix scam is now tricking Windows users into launching Windows Terminal and pasting malware into it themselves handing the credential-stealing Lumma infostealer the keys to their browser vault. |
|
Son of government contractor arrested after alleged $46M crypto heist from .. - 6/03 8:02 pm FBI and French GIGN swoop on Saint Martin, John Daghita in cuffs The son of a government contractor was arrested in the Caribbean after allegedly stealing more than $46 million in seized cryptocurrency from the US Marshals Service, the FBI says. |
|
Microsoft finally gets around to fixing Windows 10 Recovery Environment .. - 6/03 7:38 pm Released from the curse of the update bork fairy Microsoft has finally fixed a Windows Recovery Environment (WinRE) bug it introduced in Windows 10's final update. |
|
Transport for London says 2024 breach affected 7M customers, not 5,000 - 6/03 7:31 pm Attackers accessed systems holding data tied to millions of Oyster and contactless users Transport for London has confirmed that a 2024 breach exposed the data of more than 7 million people a far larger crowd than the few thousand customers originally warned that their details might be at risk. |
|
Google says spyware makers and China-linked groups dominated zero-day .. - 6/03 7:52 am Of the 90 zero-days GTIG tracked in 2025, 43 hit enterprise tech Zero-day exploitation targeting enterprise tech products reached an all-time high last year, with China-linked cyber-espionage groups remaining the most prolific state-backed users, according to Google. |
|
Iran intelligence backdoored US bank, airport, software outfit networks - 6/03 2:53 am MOIS-linked MuddyWater crew has a new, custom implant An Iranian cyber crew believed to be part of the Iranian Ministry of Intelligence and Security (MOIS) has been embedded in multiple US companies' networks - including a bank, software firm, and airport, among others - since the beginning of February, with more activity in the days following the US and Israeli military strikes, according to security researchers. |
|
UK watchdog eyes Meta's smart glasses after workers say they 'see .. - 5/03 9:08 pm Contractors tasked with improving AI reportedly had access to intimate footage captured through wearables Britain's privacy watchdog is asking questions about Meta's AI-powered smart glasses after reports that human contractors reviewing recordings from the devices were exposed to extremely private moments captured by unsuspecting users. |
|
'Hundreds' of Iranian hacking attempts have hit surveillance cameras since .. - 5/03 7:59 am Attack infrastructure attributed to 'several Iran-nexus threat actors' Multiple Iranian hacking crews have been targeting internet-connected surveillance cameras across Israel and other Middle Eastern countries since the war started on February 28, according to Check Point security researchers. |
|
Malware-laced OpenClaw installers get Bing AI search boost - 5/03 4:50 am Think before you download OpenClaw, the AI agent that can manage just about anything, is risky all by itself, but now fake installers for it are wreaking havoc. Users who searched Bings AI results for OpenClaw Windows were directed to a malicious GitHub repository that delivered information stealers and GhostSocks onto their machines. |
|
LexisNexis confirms data breach at Legal & Professional arm, some customer .. - 5/03 12:04 am Crooks claim 2 GB haul from AWS instance via React2Shell exploit Data analytics giant LexisNexis has confirmed its Legal & Professional division suffered a data breach days after the Fulcrumsec cybercrime crew claimed responsibility for the hack. |
|
Kaspersky dismisses claims Coruna iPhone exploit kit is connected to .. - 4/03 10:18 pm Follows suggestions iPhone-pwning toolset bears hallmarks of zero-days that targeted Russian diplomats Russian cybersecurity outfit Kaspersky is waving away claims that an iPhone exploit kit recently uncovered by Google was developed by the same people who were behind a group of zero-days that allegedly compromised thousands of Russian diplomats in a 2023 campaign. |
|
Google feels the need for security speed, so will ship Chrome updates .. - 4/03 10:01 am Retains eight-weekly Extended Stable releases but warns fortnightly updates are the best way to stay safe Google will halve the time between releases of its Chrome browser to two weeks, across versions of the software for desktop operating systems, Android, and iOS. |
|
Dev stunned by $82K Gemini bill after unknown API key thief goes to town - 4/03 7:19 am Probably not an isolated incident only as researchers have already found 2,863 live API keys exposed A developer says their company is on the hook for more than $82,000 in unauthorized charges after a stolen Google Gemini API key racked massive usage costs up in just 48 hours. |
|
Chat at your own risk! Data brokers are selling deeply personal bot .. - 4/03 4:59 am AI conversations for sale include sensitive health and legal details Your latest chat transcript could be bought and sold. Data brokers are selling access to sensitive personal data captured during chatbot conversations, despite claims that the data is anonymized and obtained with consent. |
|
Cyberwarriors elevated to big leagues in US war with Iran - 4/03 2:23 am No more hiding in the server closet: Cyber ops mentioned alongside kinetic warfare as critical to conflict In what may be the most public acknowledgment of its cyber operations capabilities to date, the Pentagon has admitted that cyber soldiers are playing a key role in its attacks on Iran. |
|
Turns out most cybercriminals are old enough to know better - 3/03 11:25 pm Law enforcement data shows profit-driven cybercrime is dominated by 35- to 44-year-olds, not script kiddies Contrary to what some believe, cybercrime is not a kids' game. Middle-aged adults, not teenagers, now make up the biggest chunk of people getting busted. |
|
Until last month, attackers could've stolen info from Perplexity Comet .. - 3/03 10:01 pm AI browsing agent left local files open for the taking If you wanted to steal local files from someone using Perplexity's Comet browser, until last month you could just schedule the theft by sending your victim a calendar event. |
|
Cybercriminals swipe 15.8M medical records from French doctors ministry - 3/03 7:54 pm Third-party software supplier breached leading to leak of notes Around 15.8 million administrative files were stolen after attackers breached a software supplier to France's health ministry. |
|
Chrome Gemini panel became privilege escalator for rogue extensions - 3/03 7:39 pm High-severity flaw let malicious add-ons access system via browser's embedded AI feature Security boffins have discovered a high-severity bug in Google Chrome that allowed malicious extensions to hijack its Gemini Live AI panel and inherit privileges they were never meant to have. |
|
Gamers furious as Brit studio Cloud Imperium quietly admits to data breach - 3/03 2:24 pm Slow disclosure and odd reassurance that exposing names and contact details won't be a problem isn't going down well Gamers are ready to unleash their mightiest virtual weapons and point them at British games studio Cloud Imperium, after it sat on news of a data breach and then announced it without fanfare. |
|
Phish of the day: Microsoft OAuth scams abuse redirects for malware .. - 3/03 8:33 am Crims hope for payday from malicious payloads rather than stealing access tokens Microsoft has warned organizations about ongoing OAuth abuse scams that use phishing emails and URL redirects to infect victims' machines with malware and take over their devices. |
|
Iran's cyberwar has begun - 3/03 4:52 am 'Expect elevated activity for the foreseeable future' Iranian hackers have launched spying expeditions, digital probes, and distributed denial of service (DDoS) attacks in the wake of the US and Israel launching missile strikes over the weekend, and security researchers urge organizations to expect more cyber intrusions as the war continues. |
|
UK Businesses told to brace cyber defenses amid Iran conflict risk - 3/03 2:44 am NCSC urges all to review posture as escalating tensions increase risk of indirect digital spillover The UK's cybersecurity agency is warning British organizations to brace for potential digital blowback as the Middle East conflict spills further into the online world. |
|
Memory scalpers hunt scarce DRAM with bot blitz - 2/03 10:00 pm We can remember it for you wholesale, and sell it back to you for big bucks Web scraping bots are increasing the pressure on the tech supply chain by scouring sites for DRAM, so their minders can snap up increasingly scarce inventory and resell it for a quick profit. |
|
Scammers try to SIM-swap Dubai citizens hours after Iranian missile strikes - 2/03 9:42 pm Vulnerable citizens targeted by criminals purporting to represent fake police crisis department Scammers targeted Dubai citizens mere hours after missiles struck the city, attempting to gain access to their bank accounts, police have warned. |
|
UK government's Vulnerability Monitoring System is working - fixes flow .. - 2/03 11:38 am PLUS: Firefox adds XSS protection; Leadership turnover at CISA; FTC exempts some data collection Infosec In Brief DNS vulnerabilities are being addressed 84 percent faster in the UK public sector thanks to an automated vulnerability scanning system established as part of a program kicked off early last year. |
|
South Koreas tax office apologizes for leaking seed phrase to seized crypto - 2/03 8:51 am Went from triumph at having busted tax dodgers to embarrassment at losing the proceeds South Koreas National Tax Service has apologized after it leaked passwords to a stash of stolen crypto, which parties unknown used to make off with the digi-cash. |
|
Denizens of DEF CON are 'fed up with government' - 28/02 7:11 pm Jake Braun thinks hackers need to create a 'Digital arsenal of democracy' to defend us all Interview Hackers especially Jake Braun are "fed up with government." |
|
Double whammy: Steaelite RAT bundles data theft, ransomware in one evil .. - 28/02 6:59 am Credential and cryptocurrency theft, live surveillance, ransomware - an attacker's Swiss Army knife A new remote access trojan (RAT) being sold on cybercrime networks enables double extortion attacks on Windows machines by bundling ransomware and data theft, along with credential and cryptocurrency stealers, live surveillance, and a whole host of other illicit capabilities, all controllable from a centralized dashboard. |
|
Suspected Nork digital intruders caught breaking into US healthcare, .. - 28/02 3:59 am Who is knocking at the Dohdoor? Digital intruders with possible links to North Korea have been infecting US education and healthcare sectors with a never- before-seen backdoor since at least December, according to security researchers. |
|
Ransomware payments cratered in 2025, but attacks surged to record highs - 28/02 12:15 am Smaller crews piled in as old names splintered and rebranded Ransomware payments cratered in 2025, but it seems like the cybercrooks launching the attacks didn't get the memo. |
|
French DIY etailer ManoMano admits customer data stolen - 27/02 11:15 pm Crooks claim they helped themselves to over 37M accounts during January hit on subcontractor French online marketplace ManoMano is warning customers their personal data was siphoned off after a cyberattack hit one of its customer support subcontractors and criminals are already claiming the haul is far larger than the company's carefully worded notice suggests. |
|
Cops back Dutch telco Odido after second wave of ShinyHunters leaks - 27/02 9:54 pm Company refuses to pay ransom as attackers threaten larger daily dumps The Netherlands' national police is backing Odido's refusal to pay a ransom after ShinyHunters leaked a second round of records belonging to the telco. |
|
Rapid AI-driven development makes security unattainable, warns Veracode - 26/02 11:26 pm Report claims more vulnerabilities created than fixed as remediation gap widens Veracode has posted its annual State of Software Security report, based on data from 1.6 million applications tested on its cloud platform, finding that more vulnerabilities are being created than are being fixed, and that high-velocity development with AI is making comprehensive security unattainable. |
|
Scattered Lapsus$ Hunters auditioning female voices to sharpen social .. - 26/02 8:35 pm Telegram posts promise up to $1,000 per call as gang refines IT helpdesk ruse Prolific cybercrime crew Scattered Lapsus$ Hunters (SLSH) is reportedly recruiting women in the hope of improving its social engineering success. |
|
Five Eyes warn: Patch your Cisco SD-WAN or risk root takeover - 26/02 7:39 pm A rare joint alert from all five spy agencies means serious business The Five Eyes intelligence alliance is urgently warning defenders to patch two Cisco Catalyst SD-WAN vulnerabilities used in attacks. |
|
Claude collaboration tools left the door wide open to remote code execution - 26/02 8:33 am Anthropic fixed the flaws - but the AI-enabled attack surfaces remain Security vulnerabilities in Claude Code could have allowed attackers to remotely execute code on users' machines and steal API keys by injecting malicious configurations into repositories, and then waiting for a developer to clone and open an untrustworthy project. |
| Reformasi | >> |
| Kroni | >> |
| Tabloid | >> |
| Tech | >> |
| World | >> |
| Motor Trend | >> |