///
See Also: Shopee Pay | Shutterstock

Headlines : Theregister Sec News   Page 1    



India orders infosec red alert in case Mythos sparks crime spree - 6/05 10:32 am

Securities regulator urges market players to develop new strategies and nail cyber-basics before AI models fuel mass attacks Indias Securities and Exchange Board has advised participants in the nations equities industry to immediately revisit their information security systems and practices, in case Anthropics Mythos bug-finding AI sparks a cyberattack spree.





Attackers are cashing in on fresh 'CopyFail' Linux flaw - 5/05 11:01 pm

Researchers dropped a reliable root exploit and it didnt sit idle for long CISA is warning that a newly-disclosed Linux kernel bug dubbed "CopyFail" is already being exploited, just days after researchers dropped a working root- level exploit.





Real estate giant confirms vishing incident as ShinyHunters and Qilin both .. - 5/05 9:34 pm

Cushman & Wakefield activated incident response protocols after serial extortionists issued separate threats Real estate giant Cushman & Wakefield has confirmed a data breach after two cybercrime groups, ShinyHunters and Qilin, separately claimed responsibility for attacks on the company.





ShinyHunters claims dump puts 119K Vimeo emails in the wild - 5/05 8:15 pm

Vimeo points finger at analytics supplier Anodot, says no logins or card data were touched More than 119,000 Vimeo users's email addresses were extracted in a breach traced to a third-party analytics vendor, according to Have I Been Pwned.





Romance scammers turn sweet talk into 102M payday - 5/05 7:43 pm

Victims losing 280K a day to fake profiles and sob stories Romance fraudsters scammed Britons out of 102 million ($138 million) last year, according to the latest police figures.





NHS to close-source hundreds of GitHub repos over AI, security concerns - 5/05 5:15 pm

Healthcare giant's maintainers handed May deadline to enact the change The UK's National Health Service (NHS) is ordering all of its technology leaders to temporarily wall off the organization's open source projects over concerns relating to advanced AI and Anthropic's Mythos.





Microsoft's bad obsession is showing up in shabby services and slipshod .. - 5/05 4:30 pm

If you can't bother to keep GitHub running, why should we bother with you? Opinion It's been another shabby week for Microsoft, and a shabbier one for its users. We learnt that Windows 11's epic habit of trying to corral customers into paid-for Microsoft services just got worse with a low-rent trick . Remote Desktop got a bit more secure, which is good, but in a way that suggests not too much user testing took place . As for GitHub GitHub got two helpings of Chef Redmondo's Special Sauce.





Singapore boffins get diverse SIEMs singing in harmony with agentic rule .. - 5/05 10:12 am

Vendors all use different formats. This tech translates them all so you can smooth your SOC Academics from Singapore and China have found a way to make AI useful for cyber-defenders, by creating a technique that translates rules from diverse Security Information and Event Managements (SIEMs) so theyre easier to consume across multiple systems.





Kids say they can beat age checks by drawing on a fake mustache - 5/05 4:50 am

46% say age checks are easy to bypass, and nearly a third admit getting around them Its been months since the UK government began requiring stronger age checks under the Online Safety Act, and recent research suggests those measures are falling short of keeping kids away from harmful content. In some cases, even drawing on a mustache has been reported as enough to fool age detection software.





Shadow IT has given way to shadow AI. Enter AI-BOMs - 4/05 11:04 pm

'If you don't have visibility, you can't understand what to protect' When it comes to securing enterprise supply chains, now heavily infused with AI applications and agents, a software bill of materials (SBOM) no longer provides a complete inventory of all the components in the environment. Enter AI-BOMs.





If the vote you rocked, your personal info can be grokked - 4/05 5:06 pm

Even limited voter rolls can be linked to identify people, research shows Your voter data could be used against you. A foreign intelligence service that wished to identify the family members of deployed military personnel could do so by cross-referencing public voter record data and social media posts.





Five Eyes spook shops warn rapid rollouts of agentic AI are too risky - 4/05 4:43 pm

Prioritize resilience over productivity, say CISA, NCSC and their friends from Oz, NZ, Canada Information security agencies from the nations of the Five Eyes security alliance have co-authored guidance on the use of agentic AI that warns the technology will likely misbehave and amplifies organizations existing frailties, and therefore recommend slow and careful adoption of the tech.





Brace for the patch tsunami: AI is unearthing decades of buried code debt - 2/05 4:30 pm

Britain's cyber agency says the bill for years of technical shortcuts is coming due, and it's arriving all at once Britain's cyber agency is warning that AI-fuelled bug hunting is about to flush out years of buried flaws, leaving defenders scrambling to keep up.





First reports come in of victims of critical cPanel vuln as 'millions' of .. - 1/05 9:10 pm

Exploitation was underway before patches landed, at least one victim reports ransomware demand CISA has added a critical cPanel bug to its known-exploited list, confirming that attackers are already poking holes in one of the internet's most widely used hosting stacks.





OpenAI locks GPT-5.5-Cyber behind velvet rope despite slamming Anthropic .. - 1/05 7:42 pm

Altman's crew now doing the same gatekeeping it recently mocked OpenAI is lining up a limited release of its new GPT-5.5-Cyber model to a handpicked circle of "cyber defenders," just weeks after taking a swipe at Anthropic for doing almost exactly the same thing.





Pro-Iran crew turns DDoS into shakedown as Ubuntu.com stays down - 1/05 7:21 pm

313 Team tells Canonical: pay up or the packets keep coming Canonical says its web infrastructure is under attack after a pro-Iran hacktivist group instructed its members to target the open source giant.





Passport to : Home Office adds 216M to travel doc contract before a single .. - 1/05 5:15 pm

Start date pushed back a year, annual cost up a third, and UK's now handing out eight million passports a year The Home Office has increased the annual value and overall duration of its new passport production contract, increasing it to a total of 576 million as it starts a third round of engagement with suppliers.





The never-ending supply chain attacks worm into SAP npm packages, other .. - 1/05 7:21 am

Mini Shai-Hulud caught spreading credential-stealing malware The wave of supply chain attacks aimed at security and developer tools has washed up more victims, namely SAP and Intercom npm packages, plus the lightning PyPI package.





Bot her emails: most modern phishing campaigns are AI-enabled - 1/05 4:26 am

KnowBe4 says 86% of phishing it tracked used AI, and inboxes are only the start Give a man a phishing kit and he might get lucky a couple of times; teach an AI to phish and it'll change the landscape, if KnowBe4's latest phishing trends report is accurate.





FBI cyber boss: China's hacker-for-hire ecosystem 'out of control' - 1/05 3:30 am

One alleged cyber contractor was extradited to the US over the weekend China's "hacker-for-hire ecosystem has gotten out of control," according to Brett Leatherman, assistant director of the FBI's cyber division.





Google's fix for critical Gemini CLI bug might break your CI/CD pipelines - 1/05 1:15 am

This CVSS 10.0 RCE vuln has been patched, automatically for some, so better check those workflows If you use Gemini CLI, watch out: Google has patched a CVSS 10.0 vulnerability in its command-line AI tool and is warning anyone running it in headless mode, or through GitHub Actions, to review their workflows.





French prosecutors link 15-year-old to mega-breach at states secure .. - 1/05 12:39 am

Two computer crime allegations follow up to 18M lines of data surfacing online French prosecutors say police detained a 15-year-old on April 25 over the alleged theft of millions of records from France Titres (ANTS), the agency handling secure documents.





Nearly half of UK businesses pwned last year as phishing keeps doing the .. - 30/04 7:35 pm

Turns out the real problem is not AI but staff still clicking on dodgy emails from 'IT support' Nearly half of UK businesses are still getting breached, and in many cases, the attacker's big breakthrough is an employee clicking "sure, why not" on a fake login page.





What type of 'C2 on a sleep cycle' do they leave behind? Novel Chinese spy .. - 30/04 7:00 pm

Just in time for the Trump-Xi summit Exclusive A novel China-linked threat group infiltrated more than a dozen critical networks in Poland, Asian countries, and possibly beyond, beginning in December 2024 and with activity uncovered as recently as this month.





Bug of the year (so far): Nasty cPanel vulnerability probably exploited as .. - 30/04 6:22 pm

Emergency patches out now for those managing the millions of domains assumed to be affected Emergency patches are available for a critical vulnerability in cPanel and WHM that allows attackers to bypass authentication and gain root access to servers managed using it.





Britain's 6B armoured sickener Ajax cleared for duty despite injuring .. - 30/04 4:45 pm

Investigation finds no single cause for soldiers falling ill, just bad bolts, cold air, and apparently the soldiers themselves Britain's notorious Ajax armored vehicles are being accepted back from the manufacturer after investigations found no single cause for the symptoms plaguing crews, meaning soldiers will need to grin and bear it.





Finance company stores DB credentials in helpfully labeled spreadsheet - 30/04 4:00 pm

Great idea, guys. Let's keep all of the data in an Excel file with weak password protection PWNED Welcome, once again, to PWNED, the weekly column where we recount the adventures of IT explorers who found their own pile of quicksand and then jumped right into it. This week's story involves keeping sensitive information in a very vulnerable place and then not protecting it adequately.





Linux cryptographic code flaw offers fast route to root - 30/04 8:01 am

Patches land for authencesn flaw enabling local privilege escalation Developers of major Linux distributions have begun shipping patches to address a local privilege escalation (LPE) vulnerability arising from a logic flaw.





GitHub: Zounds, a genuinely helpful AI-assisted bug report that isn't .. - 30/04 4:49 am

Claude ploughs through months of work in rapid time, helps Wiz researchers nab lucrative award Wiz researchers are set for a tidy payday thanks to their discovery of a high-severity flaw in GitHub's git infrastructure that handed remote attackers full read/write access to private GitHub repositories using a single command.





Researchers move in the right direction, develop powerful GPS interference .. - 30/04 4:11 am

ORNL says portable detector kit can separate real GPS signals from fake ones even at equal strength GPS spoofing, which sends fake satellite-like signals, and GPS jamming, which drowns receivers in noise, are increasingly serious problems. Researchers at Oak Ridge National Laboratory in Tennessee have created what they say is the most effective system yet for detecting GPS interference, which could help blunt such attacks.





Microsoft's patch for a 0-day exploited by Russian spies fell short. .. - 30/04 3:15 am

Second try's a charm? Microsoft and the US Cybersecurity and Infrastructure Security Agency (CISA) warned that attackers are exploiting a zero-click Windows flaw that can expose sensitive information on vulnerable systems.





Legacy TLS tour continues with Exchange Online blocking old versions from .. - 30/04 2:35 am

Microsoft readies the axe once again for yesterday's security Microsoft has warned users still clinging to legacy TLS versions that the end is nigh for TLS 1.0 and 1.1 on POP3 and IMAP4 connections to Exchange Online.





CISA flags data-theft bug in NSA-built OT networking tool - 29/04 11:35 pm

GrassMarlin leaks sensitive information, provided your targeting phishing skills are sharp enough The Cybersecurity and Infrastructure Security Agency (CISA) is warning anyone who uses GrassMarlin, a tool developed by the National Security Agency (NSA), about a new vulnerability that attackers can use to snoop on sensitive information.





EU waves through open source age-check tool to keep kids safe online - 29/04 8:03 pm

'Online platforms can rely on our app,' says Commish, 'there are no more excuses' The European Commission has recommended EU member states adopt an age verification app designed to protect children from harmful online content.





GoDaddy customer claims registrar transferred 27-year-old domain without .. - 29/04 6:00 pm

32 phone calls, 17 email chains, a 5-day ordeal, and no help during the daddy of all stuffups, claim those affected GoDaddy is currently investigating claims that it handed complete control of a valid 27-year-old domain to another customer, without requiring them to pass any authentication processes or upload any supporting documents.





30 ClawHub skills secretly turn AI agents into a crypto swarm - 29/04 2:32 pm

Yet another reason not to feast on OpenClaw Thirty ClawHub skills published by a single author are silently co-opting AI agents and creating a mass cryptocurrency mining swarm without any malware or user consent.





Don't pay Vect a ransom - your data's likely already wiped out - 29/04 2:53 am

'Full recovery is impossible for anyone, including the attacker' Organizations hit by the wave of Trivy and LiteLLM supply-chain compromises that paid Vect in hopes of recovering their data likely did not get much back, according to Check Point Research. That's because the ransomware Vect uses isn't actually ransomware at all, but a wiper that destroys any file larger than 128KB.





Have I Been Pwned claims Pitney Bowes hit by 8.2M email address leak - 28/04 10:15 pm

Names, phone numbers, physical addresses also included in Shiny Hunters alleged data dump Logistics technology company Pitney Bowes, which makes franking machines for US postage, is the latest scalp claimed by ShinyHunters and its ongoing spree of pay-or-leak attacks against major organizations.





SUSE's sovereignty pitch meets an inconvenient $6 billion question - 28/04 6:00 pm

Linux vendor touts European independence at SUSECON as majority stakeholder quietly explores its options European-based SUSE devoted much of the annual SUSECON event to its sovereignty-focused pitch - even as reports swirl that its majority stakeholder is exploring a $6 billion sale which could land the Linux vendor in American hands.





Ongoing supply-chain attack 'explicitly targeting' security, dev tools - 28/04 7:33 am

Vendor confirms repo data exposure after Lapsus$ claims source code, secrets dump Software security testing outfit Checkmarx has become the latest organization caught up in an ongoing attack on security-tool providers. The biz said data posted online appears to have come from one of its GitHub repositories after the Lapsus$ extortion crew claimed to have dumped the companys source code, secrets, and other sensitive data.




Reformasi     >>



Pemimpin AMK desak Anwar jelaskan pendirian isu .. - Mkini
Ketua Pemuda PKR WP, Asheeq Ali Sethi Alivi bangkit kenyataan terbaru Zahid Hamidi.
Kroni     >>



Iran lancar sistem baharu kawal selia Selat Hormuz - Harakahdaily
TEHRAN: Iran telah melancarkan sistem baharu untuk mengawal lalu lintas kapal melalui Selat Hormuz, meneruskan kebuntuan maritim yang kini melibatkan sekatan AS dan ancaman tindakan ketenteraan. Di bawah peraturan baharu itu, semua kapal yang merancang untuk melalui laluan air yang sempit itu mesti ..
Tabloid     >>



Sistem Giliran Dan Kuota Haji Tentukan Kelayakan, .. - Siakapkeli
MAKKAH, 6 Mei (Bernama) -- Sistem giliran serta agihan kuota haji menjadi asas utama Lembaga Tabung Haji (TH) dalam menentukan kelayakan jemaah Malaysia menunaika
Tech     >>



Antaramuka Liquid Glass Pada Android Diacah Sempena .. - Amanz
Adalah Android juga akan memasuki era antaramuka lutsinar seperti Liquid Glass pada peranti Apple. Ini seakan telahpun disahkan oleh Google sendiri menerusi video yang dikongsi sempena The Android Show I/O Edition yang akan diadakan pada 12 Mei depan. Acara ini akan berlangsung sebelum Google ..
World     >>



Oil prices fall as Trump pauses Hormuz escort effort - Cnbc
Oil prices fell after Trump said the U.S. would pause its naval escort endeavor in the Strait of Hormuz, raising hopes of a potential deal with Iran.
Motor Trend     >>



Geely Now Has An EV Version Of The Proton e.MAS 7 PHEV .. - DSF
It’s no secret that the Proton e.MAS 7 and Proton e.MAS 7 PHEV are based on two different Geely models. The e.MAS 7 is based on the Geely Galaxy EX5. The e.MAS 7 PHEV is based on the Geely Galaxy Starship 7. Both the Galaxy EX5 and Galaxy Starship 7 are based on the Geely […] The ..