❌

Normal view

Opsec oopsie: Dutch navy frigate location outed by mailing it a Bluetooth tracker

17 April 2026 at 16:31

Or, how public information and a €5 tracker exposed an avoidable opsec lapse

Militaries around the world spend countless hours training, developing policies, and implementing best operational security practices, so imagine the size of the egg on the face of the Dutch navy when journalists managed to track one of its warships for less than the cost of some hagelslag and a coffee.…

Received β€” 16 April 2026 ⏭ The Register - Security

North Korea targets macOS users in latest heist

16 April 2026 at 18:20

Social engineering: 'low-cost, hard to patch, and scales well'

North Korean criminals set on stealing Apple users' credentials and cryptocurrency are using a combination of social engineering and a fake Zoom software update to trick people into manually running malware on their own computers, according to Microsoft.…

Server-room lock was nothing but a crock

16 April 2026 at 08:00

Your cybersecurity is only as good as the physical security of the servers

PWNED Welcome back to Pwned, the column where we immortalize the worst vulns that organizations opened up for themselves. If you’re the kind of person who leaves your car doors unlocked with a pile of cash in the center console, this week’s story is for you.…

Google Chrome lacks protection against one of the most basic and common ways to track users online

16 April 2026 at 00:28

Browser fingerprinting is everywhere

Google markets its Chrome browser by citing its superior safety features, but according to privacy consultant Alexander Hanff, Chrome does not protect against browser fingerprinting – a method of tracking people online by capturing technical details about their browser.…

Nobody knows how many CVEs Anthropic's Project Glasswing has actually found

15 April 2026 at 21:33

Like the majority of the companies participating, it remains a mystery

Last week, Anthropic surprised the world by declaring that its latest model, Mythos, is so good at finding vulns that it would create chaos if released. Now, under the title of Project Glasswing, over 50 selected companies and orgs are allowed to test the hyped up LLM to find security holes in their own products. But just how many problems have they really discovered?…

Received β€” 15 April 2026 ⏭ The Register - Security

Agents hooked into GitHub can steal creds – but Anthropic, Google, and Microsoft haven't warned users

15 April 2026 at 08:01

Researchers who found the flaws scored beer money bounties and warn the problem is probably pervasive

Exclusive Security researchers hijacked three popular AI agents that integrate with GitHub Actions by using a new type of prompt injection attack to steal API keys and access tokens, and the vendors who run agents didn’t disclose the problem.…

Commvault has a Ctrl+Z for rogue AI agents

14 April 2026 at 20:57

The company's new software keeps an eye on your agents and backs up data.

Keep your agents close and your agent-monitoring software closer. Commvault’s new AI Protect can discover and monitor AI agents running inside AWS, Azure, and GCP environments and even roll back their actions when something goes wrong.…

❌