///
See Also: Shutterstock

Headlines : Theregister Sec News   Page 1    



Attackers finally get around to exploiting critical Microsoft bug from 2024 - 14/02 2:45 am

As if admins haven't had enough to do this week Ignore patches at your own risk. According to Uncle Sam, a SQL injection flaw in Microsoft Configuration Manager patched in October 2024 is now being actively exploited, exposing unpatched businesses and government agencies to attack.





Top Dutch telco Odido admits 6.2M customers caught in contact system caper - 13/02 7:45 pm

Names, addresses, bank account numbers accessed but biz insists passwords and call data untouched The Netherlands' largest mobile network operator (MNO) has admitted that a breach of its customer contact system may have affected around 6.2 million people.





Enforcing piracy policy earned helpdesk worker death threats - 13/02 3:27 pm

Years later, he read about his antagonist doing time for murder On Call Welcome to another installment of On Call, The Register's weekly reader- contributed column that tells your tech support tales.





30+ Chrome extensions disguised as AI chatbots steal users' API keys, .. - 13/02 6:59 am

Are you a good bot or a bad bot? More than 30 malicious Chrome extensions installed by at least 260,000 users purport to be helpful AI assistants, but they steal users' API keys, email messages, and other personal data. Even worse: many of these are still available on the Chrome Web Store as of this writing.





Who's the bossware? Ransomware slingers like employee monitoring tools, too - 13/02 4:07 am

As if snooping on your workers wasn't bad enough Your supervisor may like using employee monitoring apps to keep tabs on you, but crims like the snooping software even more. Threat actors are now using legit bossware to blend into corporate networks and attempt ransomware deployment.





Apple patches decade-old iOS zero-day, possibly exploited by commercial .. - 12/02 10:10 pm

Flaw abused 'in an extremely sophisticated attack against specific targeted individuals' Apple patched a zero-day vulnerability affecting every iOS version since 1.0, used in what the company calls an "extremely sophisticated attack" against targeted individuals.





Supply chain attacks now fuel a 'self-reinforcing' cybercrime economy - 12/02 7:59 pm

Researchers say breaches link identity abuse, SaaS compromise, and ransomware into a cascading cycle Cybercriminals are turning supply chain attacks into an industrial-scale operation, linking breaches, credential theft, and ransomware into a "self-reinforcing" ecosystem, researchers say.





Feeling brave? Ministry of Defence seeks 300K digital boss to manage 4.6B .. - 12/02 6:15 pm

Whoever gets it will steer UK department's IT, AI strategy, and megabucks vendor deals The UK Ministry of Defence (MoD) is offering between 270,000 to 300,000 for a senior digital leader who will oversee more than 4.6 billion in spend





Google: China's APT31 used Gemini to plan cyberattacks against US orgs - 12/02 3:00 pm

Meanwhile, IP-stealing 'distillation attacks' on the rise A Chinese government hacking group that has been sanctioned for targeting America's critical infrastructure used Google's AI chatbot, Gemini, to auto-analyze vulnerabilities and plan cyberattacks against US organizations, the company says.





Microsoft warns that poisoned AI buttons and links may betray your trust - 12/02 9:07 am

Businesses are embedding prompts that produce content they want you to read, not the stuff AI makes if left to its own devices Amid its ongoing promotion of AIs wonders, Microsoft has warned customers it has found many instances of a technique that manipulates the technology to produce biased advice.





Devilish devs spawn 287 Chrome extensions to flog your browser history to .. - 12/02 5:23 am

Add-ons with 37M installs leak visited URLs to 30+ recipients, researcher says They know where you've been and they're going to share it. A security researcher has identified 287 Chrome extensions that allegedly exfiltrate browsing history data for an estimated 37.4 million installations.





Posting AI-generated caricatures on social media is risky, infosec .. - 12/02 2:56 am

The more you share online, the more you open yourself to social engineering If you've seen the viral AI work pic trend where people are asking ChatGPT to "create a caricature of me and my job based on everything you know about me" and sharing it to social, you might think it's harmless. You'd be wrong.





Payroll pirates are conning help desks to steal workers' identities and .. - 12/02 12:17 am

Attackers using social engineering to exploit business processes, rather than tunnelling in via tech Exclusive When fraudsters go after people's paychecks, "every employee on earth becomes a target," according to Binary Defense security sleuth John Dwyer.





Were telcos tipped off to *that* ancient Telnet bug? Cyber pros say the .. - 11/02 11:41 pm

Curious port filtering and traffic patterns suggest advisories werent the earliest warning signals sent Telcos likely received advance warning about January's critical Telnet vulnerability before its public disclosure, according to threat intelligence biz GreyNoise.





Notepad's new Markdown powers served with a side of remote code execution - 11/02 7:31 pm

Smug faces across all those who opposed the WordPad-ification of Microsoft's humble text editor Just months after Microsoft added Markdown support to Notepad, researchers have found the feature can be abused to achieve remote code execution (RCE).





Legacy systems blamed as ministers promise no repeat of Afghan breach - 11/02 5:30 pm

UK government grilled over progress made to prevent a second life-threatening leak Legacy IT issues are hampering key technical measures designed to prevent highly sensitive data leaks, UK government officials say.





Microsoft's Valentine's gift to admins: 6 exploited zero-day fixes - 11/02 6:10 am

Roses are red, violets are blue ... now get patching What better way to say I love you than with an update? Attackers exploited a whopping six Microsoft bugs as zero-days prior to Redmond releasing software fixes on February's Patch Tuesday.





AI agents spill secrets just by previewing malicious links - 11/02 1:55 am

Zero-click prompt injection can leak data when AI agents meet messaging apps, researchers warn AI agents can shop for you, program for you, and, if you're feeling bold, chat for you in a messaging app. But beware: attackers can use malicious prompts in chat to trick an AI agent into generating a data-leaking URL, which link previews may fetch automatically.





Singapore spent 11 months booting China-linked snoops out of telco networks - 10/02 9:43 pm

Operation Cyber Guardian involved 100-plus staff across government and industry Singapore spent almost a year flushing a suspected China-linked espionage crew out of its telecom networks in what officials describe as the country's largest cyber defense operation to date.





Nearly 17,000 Volvo staff dinged in supplier breach - 10/02 7:09 pm

HR outsourcer Conduent confirms intruders accessed benefits-related records tied to US personnel Nearly 17,000 Volvo employees had their personal data exposed after cybercriminals breached Conduent, an outsourcing giant that handles workforce benefits and back-office services.





British Army splashes $86M on AI gear to speed up the battlefield kill .. - 10/02 6:00 pm

Troops fitted with new comms kit as part of Project ASGARD British soldiers are to get an array of AI-ready kit that should mean they don't have to wait to see the "whites of their eyes" before pulling the trigger.





Someone's attacking SolarWinds WHD to steal highprivilege credentials - .. - 10/02 5:54 am

So many CVEs, so little time Digital intruders exploited buggy SolarWinds Web Help Desk (WHD) instances in December to break into victims' IT environments, move laterally, and steal high-privilege credentials, according to Microsoft researchers.





More than 135,000 OpenClaw instances exposed to internet in latest .. - 10/02 1:23 am

By default, the bot listens on all network interfaces, and many users never change it It's a day with a name ending in Y, so you know what that means: Another OpenClaw cybersecurity disaster.





Dutch data watchdog snitches on itself after getting caught in Ivanti .. - 9/02 10:50 pm

Staff data belonging to the regulator and judiciary's governing body accessed The Dutch Data Protection Authority (AP) says it was one of the many organizations popped when attackers raced to exploit recent Ivanti vulnerabilities as zero-days.





Taiwan tells Uncle Sam its chip ecosystem ain't going anywhere - 9/02 10:02 pm

Moving 40% of semiconductor production to America is 'impossible' says vice premier Taiwan's vice-premier has ruled out relocating 40 percent of the country's semiconductor production to the US, calling the Trump administration's goal "impossible."





How the GNU C Compiler became the Clippy of cryptography - 9/02 8:07 pm

Security devs forced to hide Boolean logic from overeager optimizer FOSDEM 2026 The creators of security software have encountered an unlikely foe in their attempts to protect us: modern compilers.





Follow the money: Switzerland remains Europe's top destination for tech pay - 9/02 7:42 pm

Average Swiss salaries dwarf those on offer across the rest of the continent European techies looking for the biggest payday are far better off in Switzerland than anywhere else, with average salaries eclipsing all other countries on the continent.





European Commission probes intrusion into staff mobile management backend - 9/02 6:37 pm

Officials explore issue affecting infrastructure after CERT-EU detected suspicious activity Brussels is digging into a cyber break-in that targeted the European Commission's mobile device management systems, potentially giving intruders a peek inside the official phones carried by EU staff.





Indian police commissioner wants ID cards for AI agents - 9/02 12:08 am

PLUS: China broadens cryptocurrency crackdown; Australian facial recognition privacy revisited; Singapore debuts electric VT





Telcos aren't saying how they fought back against China's Salt Typhoon .. - 9/02 6:25 am

PLUS: OpenClaw teams with VirusTotal; Crypto kidnappings in France; Critical vulns at SmarterMail; And more Infosec In Brief So-hot-right-now AI assistant OpenClaw, which is very much not secure right now , has teamed up with security scanning service VirusTotal.





Study confirms experience beats youthful enthusiasm - 7/02 8:30 pm

Research shows productivity and judgment peak decades after graduation A growing body of research continues to show that older workers are generally more productive than younger employees.





Flickr emails users about data breach, pins it on 3rd party - 7/02 12:56 am

Attackers may have snapped user locations and activity information, message warns Legacy image-sharing website Flickr suffered a data breach, according to customers emails seen by The Register .





DDoS deluge: Brit biz battered as botnet blitzes break records - 7/02 12:36 am

UK leaps to sixth in global flood charts as mega-swarm unleashes 31.4 Tbps Yuletide pummeling Cloudflare says DDoS crews ended 2025 by pushing traffic floods to new extremes, while Britain made an unwelcome leap of 36 places to become the world's sixth-most targeted location.





Cloud sovereignty is no longer just a public sector concern - 6/02 10:56 pm

Businesses still chase the cheapest option, but politics and licensing shocks are changing priorities, says OpenNebula Interview Sovereignty remains a hot topic in the tech industry, but interpretations of what it actually means and how much it matters vary widely between organizations and sectors. While public bodies are often driven by regulation and national policy, the private sector tends to take a more pragmatic, cost-focused view.





Italy claims cyberattacks 'of Russian origin' are pelting Winter Olympics - 6/02 7:28 pm

Right on cue, petulant hacktivists attempt to disrupt yet another global sporting event Italy's foreign minister says the country has already started swatting away cyberattacks from Russia targeting the Milano Cortina Winter Olympics.





Ad blocking is alive and well, despite Chrome's attempts to make it harder - 6/02 8:39 am

The end isn't nigh after all Chrome's latest revision of its browser extension architecture, known as Manifest v3 (MV3), was widely expected to make content blocking and privacy extensions less effective than its predecessor, Manifest v2 (MV2).





OpenClaw reveals meaty personal information after simple cracks - 6/02 7:32 am

Skills marketplace is full of stuff - like API keys and credit card numbers - that crims will find tasty Another day, another vulnerability (or two, or 200) in the security nightmare that is OpenClaw.





Substack says intruder lifted emails, phone numbers in months-old breach - 6/02 3:54 am

Contact details were accessed in an intrusion that went undetected for months, the blogging outfit says Newsletter platform Substack has admitted that an intruder swiped user contact details months before the company noticed, forcing it to warn writers and readers that their email addresses and other account metadata were accessed without permission.





Asia-based government spies quietly broke into critical networks across 37 .. - 6/02 3:21 am

And their toolkit includes a new, Linux kernel rootkit A state-aligned cyber group in Asia compromised government and critical infrastructure organizations across 37 countries in an ongoing espionage campaign, according to security researchers.





Betterment breach may expose 1.4M users after social engineering attack - 6/02 12:25 am

Breach-tracking site flags dataset following impersonation-based intrusion Breach-tracking site Have I Been Pwned (HIBP) claims a cyberattack on Betterment affected roughly 1.4 million users although the investment company has yet to publicly confirm how many customers were affected by January's intrusion.




Reformasi     >>



13 pemimpin Bersatu lain turut dipecat - Harapandaily
Selain daripada Ketua Pembangkang Datuk Seri Hamzah Zainudin dan tiga ahli parlimen, 13 lagi pemimpin Bersatu telah dipecat semalam. Kesemua 13 pemimpin Bersatu tersebut adalah seperti berikut: Ahli Majlis Tertinggi Bersatu, Zulkifli BujangKetua Pembangkang Melaka, Dr Yadzil YaakubAdun Sungai Manik, Zainol ..
Kroni     >>



Lebih 100 bahagian Bersatu bubar? - Utusan
KANGAR: Parti Pribumi Bersatu Malaysia (Bersatu) berdepan perpecahan besar-besaran dan berkemungkinan lumpuh ekoran gelombang penolakan akar umbi terhadap Presiden, Tan Sri Muhyiddin Yassin susulan pemecatan Datuk Seri Hamzah Zainudin daripada parti. Bekas Timbalan Pengerusi Tetap Bersatu, Datuk Hashim Suboh ..
Tabloid     >>



Isu minyak paket dibeli warga asing, individu persoal .. - Mdateline
Satu rakaman video yang tular di media sosial mendakwa berlaku pembelian minyak masak paket bersubsidi oleh warga asing di sebuah pasar raya di Bangi. Menerusi ... Baca Artikel Penuh
Tech     >>



Samsung's wide Galaxy Z Fold spotted in One UI 9 - Gsmarena
Samsung is reportedly working on a wide Galaxy Z Fold, and last year, some speculative renders showed us what this foldable smartphone could look like. However, thanks to One UI 9, we are now getting our best look yet at the wide Galaxy Z Fold. One UI 9 test builds for Samsung's unannounced Galaxy Z ..
World     >>



Iranian, Russian, and Chinese diplomats hold talks on .. - Tehrantimes
TEHRAN - The ambassadors of Iran, Russia, and China to international organizations in Vienna have held another round of talks on the latest developments related to Irans nuclear program.
Motor Trend     >>



Buletin Toyota Highlander Bev 2027 Didedahkan – .. - Mekanika
# TOYOTA HIGHLANDER BEV 2027 DIDEDAHKAN - TAWAR JARAK GERAK SEHINGGA 515KM **Toyota akhirnya membawa nama Highlander ke era elektrik sepenuhnya apabila memperkenalkan Highlander BEV baharu bagi tahun model 2027, lengkap dengan tiga baris tempat duduk.** SUV yang pernah menjadi pilihan utama ..