///
See Also: Shutterstock

Headlines : Theregister Sec News   Page 1    



UK border tech budget swells by 100M as Home Office targets small boat .. - 24/01 5:29 pm

Drone, satellite, and other data combined to monitor unwanted vessels The UK Home Office is spending up to 100 million on intelligence tech in part to tackle the so-called "small boats" issue of refugees and irregular immigrants coming across the English Channel.





CISA won't attend infosec industry's biggest conference this year - 24/01 8:22 am

But ex-CISA boss and new RSAC CEO Jen Easterly will be there exclusive The US Cybersecurity and Infrastructure Security Agency won't attend the annual RSA Conference in March, an agency spokesperson confirmed to The Register .





Patch or die: VMware vCenter Server bug fixed in 2024 under attack today - 24/01 6:04 am

If you skipped it back then, nows a very good time You've got to keep your software updated. Some unknown miscreants are exploiting a critical VMware vCenter Server bug more than a year after Broadcom patched the flaw.





Surrender as a service: Microsoft unlocks BitLocker for feds - 24/01 4:41 am

If you're serious about encryption, keep control of your encryption keys If you think using Microsoft's BitLocker encryption will keep your data 100 percent safe, think again. Last year, Redmond reportedly provided the FBI with encryption keys to unlock the laptops of Windows users charged in a fraud indictment.





ShinyHunters claims Okta customer breaches, leaks data belonging to 3 orgs - 24/01 3:18 am

'A lot more' victims to come, we're told ShinyHunters has claimed responsibility for an Okta voice-phishing campaign during which the extortionist crew allegedly gained access to Crunchbase and Betterment.





AI-powered cyberattack kits are 'just a matter of time,' warns Google exec - 24/01 1:10 am

Security chief says criminals are already automating workflows, with full end- to-end tools likely within years CISOs must prepare for "a really different world" where cybercriminals can reliably automate cyberattacks at scale, according to a senior Googler.





Fortinet admits FortiGate SSO bug still exploitable despite December patch - 23/01 8:43 pm

Fix didn't quite do the job attackers spotted logging in Fortinet has confirmed that attackers are actively bypassing a December patch for a critical FortiCloud single sign-on (SSO) authentication flaw after customers reported suspicious logins on devices supposedly fully up to date.





London boroughs limping back online months after cyberattack - 23/01 6:34 pm

Direct debits? Maybe February. Birth certificates? Dream on. Council tax bills? Oh, those are coming Hammersmith & Fulham Council says payments are now being processed as usual, two months after a cyberattack that affected multiple boroughs in the UK's capital city.





Marching orders delayed: Veterans' Digital ID off to a slow start - 23/01 5:28 pm

Much owed to the few, but takeup is under 1% More than 15,000 former members of the UK's armed forces have successfully applied for a digital version of their veterans ID card since its launch in October, according to the Government Digital Service (GDS).





Crims hit the easy button for Scattered-Spider style helpdesk scams - 23/01 7:08 am

Teach a crook to phish Criminals can more easily pull off social engineering scams and other forms of identity fraud thanks to custom voice-phishing kits being sold on dark web forums and messaging platforms.





Crims compromised energy firms' Microsoft accounts, sent 600 phishing .. - 23/01 3:18 am

Logging in, not breaking in Unknown attackers are abusing Microsoft SharePoint file-sharing services to target multiple energy-sector organizations, harvest user credentials, take over corporate inboxes, and then send hundreds of phishing emails from compromised accounts to contacts inside and outside those organizations.





FortiGate firewalls hit by silent SSO intrusions and config theft - 23/01 12:07 am

Admins say attackers are still getting in despite recent patches FortiGate firewalls are getting quietly reconfigured and stripped down by miscreants who've figured out how to sidestep SSO protections and grab sensitive settings right out of the box.





Europe's GDPR cops dished out 1.2B in fines last year as data breaches .. - 22/01 9:39 pm

Regulators logged over 400 personal data breach notifications a day for first time since law came into force GDPR fines pushed past the 1 billion (1.2 billion) mark in 2025 as Europe's regulators were deluged with more than 400data breach notifications a day, according to a new survey that suggests the post-plateau era of enforcement has well and truly arrived.





Bank of England: Financial sector failing to implement basic cybersecurity .. - 22/01 9:23 pm

Mind the cyber gap similar flaws highlighted multiple years in a row Concerned about the orgs that safeguard your money? The UK's annual cybersecurity review for 2025 suggests you should be. Despite years of regulation, financial organizations continue to miss basic cybersecurity safeguards.





Ancient telnet bug happily hands out root to attackers - 22/01 8:13 pm

Critical vuln flew under the radar for a decade A recently disclosed critical vulnerability in the GNU InetUtils telnet daemon (telnetd) is "trivial" to exploit, experts say.





Another week, another emergency patch as Cisco plugs Unified Comms zero-day - 22/01 6:54 pm

The critical-rated flaw leaves unpatched systems open to full takeover Cisco has finally shipped a fix for a critical-rated zero-day in its Unified Communications gear, a flaw that's already being weaponized in the wild, and which CISA previously flagged as an emergency priority.





Davos discussion mulls how to keep AI agents from running wild - 22/01 7:04 am

Where the shiny new FOMO object collides with insider-threat reality AI agents arrived in Davos this week with the question of how to secure them - and prevent agents from becoming the ultimate insider threat - taking center stage during a panel discussion on cyber threats.





Don't click on the LastPass 'create backup' link - it's a scam - 22/01 2:10 am

Phishing campaign tries to reel in master passwords Password managers make great targets for attackers because they can hold many of the keys to your kingdom. Now, LastPass has warned customers about phishing emails claiming that action is required ahead of scheduled maintenance and told them not to fall for the scam.





Everest ransomware gang said to be sitting on mountain of Under Armour data - 21/01 11:29 pm

Have I Been Pwned reckons 72.7M customer accounts affected, sportswear firm remains silent Have I Been Pwned (HIBP) says 72.7 million accounts registered with Under Armour were affected by an alleged ransomware attack in November.





EU considers whether there's Huawei of axing Chinese kit from networks .. - 21/01 9:42 pm

Still dominant in Germany's networks, among others The European Commission (EC) wants a revised Cybersecurity Act to address any threats posed by IT and telecoms kit from third-country sources, potentially forcing member states to confront the thorny issue of suppliers such Huawei in their national networks.





Ireland wants to give its cops spyware, ability to crack encrypted messages - 21/01 9:05 pm

Its very own Snoopers Charter comes a month after proposed biometric tech expansion The Irish government is planning to bolster its police's ability to intercept communications, including encrypted messages, and provide a legal basis for spyware use.





Best of British: UK's infosec envoys include Cisco, Palo Alto, and .. - 21/01 8:31 pm

Minister unwraps ambassadors of the Software Security Code of Practice Britain's digital economy minister has sent forth a raft of companies as "ambassadors" to help organizations across the land embrace the UK's Software Security Code of Practice.





Curl shutters bug bounty program to remove incentive for submitting AI slop - 21/01 2:25 pm

Maintainer hopes hackers send bug reports anyway, will keep shaming silly' ones The maintainer of popular open-source data transfer tool cURL has ended the projects bug bounty program after maintainers struggled to assess a flood of AI-generated contributions.





Cloudflare whacks WAF bypass bug that opened side door for attackers - 21/01 7:05 am

ACME validation had a challenge-request hole Cloudflare has fixed a flaw in its web application firewall (WAF) that allowed attackers to bypass security rules and directly access origin servers, which could lead to data theft or full server takeover.





Remember VoidLink, the cloud-targeting Linux malware? An AI agent wrote it - 21/01 2:48 am

AI + skilled malware developers = security threat VoidLink, the newly spotted Linux malware that targets victims' clouds with 37 evil plugins, was generated "almost entirely by artificial intelligence" and likely developed by just one person, according to the research team that discovered the do-it-all implant.





AI framework flaws put enterprise clouds at risk of takeover - 20/01 10:00 pm

Update Chainlit to the latest version ASAP Two "easy-to-exploit" vulnerabilities in the popular open-source AI framework Chainlit put major enterprises' cloud environments at risk of leaking data or even full takeover, according to cyber-threat exposure startup Zafran.





Anthropic quietly fixed flaws in its Git MCP server that allowed for .. - 20/01 9:00 pm

Prompt injection for the win Anthropic has fixed three bugs in its official Git MCP server that researchers say can be chained with other MCP tools to remotely execute malicious code or overwrite files via prompt injection.





For the price of Netflix, crooks can now rent AI to run cybercrime - 20/01 8:32 pm

Group-IB says crims forking out for Dark LLMs, deepfak





Akamai CEO wants help to defeat piracy, reckons he can handle edge AI alone - 20/01 12:55 am

OG CDN boss says fighting illegal streams is about stopping criminals cashing in, not free speech Interview After Cloudflare CEO Matthew Prince recently threatened to disrupt the Winter Olympics to protect free speech after Italian authorities fined his company for not disrupting pirate video streams, rival CDN provider Akamais CEO Dr. Tom Leighton fired back with what reads a lot like thinly veiled criticism.





Broker who sold malware to the FBI set for sentencing - 20/01 12:36 am

Feras Albashiti faces 10 years after $20,000 in sales to undercover agent exposed ransomware ties A Jordanian national faces sentencing in the US after pleading guilty to acting as an initial access broker (IAB) for various cyberattacks.





Don't underestimate pro-Russia hacktivists, warns UK's cyber crew - 19/01 9:37 pm

Theyre not the most sophisticated, but even simple attacks can lead to costly consequences The UK's National Cyber Security Centre (NCSC) is once again warning that pro-Russia hacktivists are a threat to critical services operators.





Windows 11 shutdown bug forces Microsoft into out-of-band damage control - 19/01 9:05 pm

Ships emergency update to fix a Patch Tuesday misfire that prevented systems from switching off Microsoft has rushed out an out-of-band Windows 11 update after January's Patch Tuesday broke something as fundamental as turning PCs off.





Ingram Micro admits summer ransomware raid exposed thousands of staff .. - 19/01 8:32 pm

Maine filing confirms July attack affected 42,521 employees and job applicants Ingram Micro disclosed that a July 2025 ransomware attack compromised the personal data of tens of thousands of employees.





UK prime minister stares down barrel of ban on social media for kids - 19/01 7:55 pm

Labour's latest U-turn? 61 backbenchers pile pressure for Starmer to back Tory peer's amendment The British government may impose a ban on under-16s using social media, despite Labour prime minister Keir Starmer having previously expressed skepticism over the measure.





Warwickshire school to reopen after cyberattack crippled IT - 19/01 7:15 pm

Kids return to classrooms after safety infrastructure knocked out A Warwickshire secondary school says it will fully reopen this week after a cyberattack forced a prolonged closure though staff will return to classrooms with "very limited access" to IT systems.





Royal Navy's helicopter drone makes its first autonomous flight - 19/01 6:15 pm

Capable of carrying 1-ton payload and key to strategy protecting North Atlantic from Russian submarines The Royal Navy has conducted the first flight of a helicopter-sized autonomous drone that is planned to operate from its ships in support of missions, including hunting for hostile submarines.





ATM maintenance tech broke the bank by forgetting to return a key - 19/01 3:30 pm

Bank staff wore the blame for a silly security slip Who, Me? Welcome to another edition of Who Me?, The Register s Monday column that shares your mistakes and celebrates your escapes.





Microsoft hiring energy strategists to power its Asian datacenters - 19/01 10:11 am

PLUS: ASUS gets into healthcare gadgets; Vietnams first fab; Australia's child social ban takes out 4.7 million accounts; And more! Asia In Brief Microsoft is hiring senior managers to ensure its datacenters in Asia can access the energy they need.





Mandiant releases quick credential cracker, to hasten the death of a bad .. - 19/01 7:57 am

PLUS: Navy spy sent to brig for 200 months in brig; Black Axe busted again; Bill aims to crimp ICE ap





Fast Pair, loose security: Bluetooth accessories open to silent hijack - 17/01 8:26 pm

Sloppy implementation of Google spec leaves 'hundreds of millions' of devices vulnerable Hundreds of millions of wireless earbuds, headphones, and speakers are vulnerable to silent hijacking due to a flaw in Google's Fast Pair system that allows attackers to seize control without the owner ever touching the pairing button.




Reformasi     >>



Kemenangan BN cerminan keyakinan rakyat - Harapandaily
Kemenangan Barisan Nasional dalam Pilihan Raya Kecil (PRK) Parlimen Kinabatangan dan DUN Lamag mencerminkan keyakinan rakyat terhadap usaha berterusan ditunjukkan di peringkat akar umbi. Perdana Menteri, Datuk Seri Anwar Ibrahim berkata, Kemenangan ini wajar ditanggapi dengan sikap tanggungjawab sebagai ..
Kroni     >>



Pearly-Thinaah juara Indonesia Masters - Utusan
PETALING JAYA: Beregu wanita No. 2 dunia, Pearly Tan-M. Thinaah tidak perlu memerah keringat untuk dinobatkan sebagai juara pada perlawanan akhir Kejohanan Badminton Indonesia Masters di Jakarta, Indonesia, hari ini. Gandingan No. 1 negara itu yang menjadi pilihan menjuarai kejohanan berstatus Super 500 ..
Tabloid     >>



Okay Mandul Isu Dengan Puteri Balqis, Individu .. - Ohmedia
Individu dikecam selepas tinggalkan komen hina soal zuriat Janna Nick dalam isu bersama Puteri Balqis. The post Okay Mandul Isu Dengan Puteri Balqis, Individu Dikecam Gara-Gara Serang Soal Zuriat Janna Nick appeared first on Oh! Media .
Tech     >>



Apple Akan Papar Lebih Iklan Melalui App Store Mulai .. - Amanz
Apple sebelum ini sedia mengumumkan akan menambah lebih banyak paparan dan pilihan iklan melalui kedai aplikasi mereka, Apple App Store. Kini, Apple mengemaskini mengatakan integrasi iklan ini akan mula berkuat-kuasa Mac 2026 ini. Apple sedia menekankan yang mana ramai menemui aplikasi baharu ..
World     >>



Trump says UK soldiers in Afghanistan 'among greatest .. - BBC
The US president's praise follows his claim that allied forces avoided the front lines during the Afghanistan conflict.
Motor Trend     >>



ZEEKR 7X Off-Road Weekend: Pandu Uji ZEEKR 7X Di Sepang - Careta
ZEEKR Malaysia turut berkongsi prestasi jualan tahun lalu, memaklumkan bahawa jumlah jualan keseluruhan ZEEKR di Malaysia pada tahun 2025 melebihi 2,500 unit, dengan sekitar 70% daripada angka tersebut disumbangkan oleh model ZEEKR 7X. Selain itu, ZEEKR Malaysia memaklumkan varian ZEEKR 7X