FreshRSS

πŸ”’
❌ Secure Planet Training Courses Updated For 2019 - Click Here
There are new available articles, click to refresh the page.
☐ β˜† βœ‡ The Register - Security

UK regulators swarm X after Grok generated nudes from photos

β€” January 8th 2026 at 12:40

Lawyers say Musk's platform may face punishment under Online Safety Act priority offenses

Elon Musk's X platform is under fire as UK regulators close in on mounting reports that the platform's AI chatbot, Grok, is generating sexual imagery without users' consent.…

☐ β˜† βœ‡ The Register - Security

Maximum-severity n8n flaw lets randos run your automation server

β€” January 8th 2026 at 11:40

Unauthenticated RCE means anyone on the network can seize full control

A maximum-severity bug in the popular automation platform n8n has left an estimated 100,000 servers wide open to complete takeover, courtesy of a flaw so bad it doesn't even require logging in.…

☐ β˜† βœ‡ The Register - Security

OpenAI putting bandaids on bandaids as prompt injection problems keep festering

β€” January 8th 2026 at 11:01

Happy Groundhog Day!

Security researchers at Radware say they've identified several vulnerabilities in OpenAI's ChatGPT service that allow the exfiltration of personal information.…

☐ β˜† βœ‡ The Register - Security

Are criminals vibe coding malware? All signs point to yes

β€” January 8th 2026 at 11:00

They also hallucinate when writing ransomware code

Interview With everyone from would-be developers to six-year-old kids jumping on the vibe coding bandwagon, it shouldn't be surprising that criminals like automated coding tools too.…

☐ β˜† βœ‡ The Register - Security

Logitech macOS mouse mayhem traced to expired dev certificate

β€” January 8th 2026 at 09:30

Company says it dropped the ball, apologizes for wasting people's time

Logitech says an expired developer certificate is to blame after swaths of customers were left infuriated when their mice malfunctioned.…

☐ β˜† βœ‡ The Register - Security

Cloudflare pours cold water on β€˜BGP weirdness preceded US attack on Venezuela’ theory

β€” January 8th 2026 at 06:00

Suggests rotten routing, not evidence of a cyber-strike before kinetic action

Cloudflare has poured cold water on a theory that the USA’s incursion into Venezuela coincided with a cyberattack on telecoms infrastructure.…

☐ β˜† βœ‡ The Register - Security

IBM's AI agent Bob easily duped to run malware, researchers show

β€” January 7th 2026 at 22:04

Prompt injection lets risky commands slip past guardrails

IBM describes its coding agent thus: "Bob is your AI software development partner that understands your intent, repo, and security standards." Unfortunately, Bob doesn't always follow those security standards.…

☐ β˜† βœ‡ The Register - Security

ESA calls cops as crims lift off 500 GB of files, say security black hole still open

β€” January 7th 2026 at 18:02

Two weeks, two major data leaks … not a good look for the European Space Agency

exclusive The European Space Agency on Wednesday confirmed yet another massive security breach, and told The Register that the data thieves responsible will be subject to a criminal investigation. And this could be a biggie.…

☐ β˜† βœ‡ The Register - Security

Stalkerware slinger pleads guilty for selling snooper software to suspicious spouses

β€” January 7th 2026 at 17:32

pcTattletale boss Bryan Fleming faces up to 15 years in prison when sentenced later this year

The US government has secured a guilty plea from a stalkerware maker in federal court, marking just the second time in more than a decade that the US has managed to prosecute a consumer spyware vendor successfully. …

☐ β˜† βœ‡ The Register - Security

Microsoft scraps Exchange Online spam clamp after customers cry foul

β€” January 7th 2026 at 15:25

Negative feedback sinks Redmond's plan to cap outbound email recipients

Microsoft has backed away from planned changes to Exchange Online after customers objected to limits designed to curb outbound email abuse.…

☐ β˜† βœ‡ The Register - Security

Ministry of Justice splurged Β£50M on security – still missed Legal Aid Agency cyberattack

β€” January 7th 2026 at 12:28

High-risk system compromised long before intrusion was finally spotted

Updated The UK's Ministry of Justice spent Β£50 million ($67 million) on cybersecurity improvements at the Legal Aid Agency (LAA) before the high-profile cyberattack it disclosed last year.…

☐ β˜† βœ‡ The Register - Security

Jaguar Land Rover wholesale volumes plummet 43% in cyberattack aftermath

β€” January 7th 2026 at 11:50

Production halts and supply-chain disruption left luxury automaker reeling in fiscal Q3

Brit luxury automaker Jaguar Land Rover has reported devastating preliminary Q3 results that lay bare the cascading consequences of a crippling cyberattack, revealing wholesale volumes collapsed more than two-fifths year-on-year.…

☐ β˜† βœ‡ The Register - Security

HSBC app takes a dim view of sideloaded Bitwarden installations

β€” January 7th 2026 at 10:13

Customers report being locked out after grabbing the password manager via F-Droid

Some HSBC mobile banking customers in the UK report being locked out of the bank's app after installing the Bitwarden password manager via an open source app catalog.…

☐ β˜† βœ‡ The Register - Security

HackerOne 'ghosted' me for months over $8,500 bug bounty, says researcher

β€” January 7th 2026 at 00:17

Long after CVEs issued and open source flaws fixed

Last fall, Jakub Ciolek reported two denial-of-service bugs in Argo CD, a popular Kubernetes controller, via HackerOne's Internet Bug Bounty (IBB) program. Both were assigned CVEs and have since been fixed. But instead of receiving an $8,500 reward for the two flaws, Ciolek says, HackerOne ghosted him for months.…

☐ β˜† βœ‡ The Register - Security

Brightspeed investigates breach as crims post stolen data for sale

β€” January 6th 2026 at 20:54

Crimson Collective claims 'sophisticated attack'

Internet service provider Brightspeed confirmed that it's investigating criminals' claims that they stole more than a million customers' records and have listed them for sale for three bitcoin, or about $276,370. …

☐ β˜† βœ‡ The Register - Security

Fake Windows BSODs check in at Europe's hotels to con staff into running malware

β€” January 6th 2026 at 14:19

Phishers posing as Booking.com use panic-inducing blue screens to bypass security controls

Russia-linked hackers are sneaking malware into European hotels and other hospitality outfits by tricking staff into installing it themselves through fake Windows Blue Screen of Death (BSOD) crashes.…

☐ β˜† βœ‡ The Register - Security

Crypto wallet shop Ledger confirms customer data lifted in Global-e snafu

β€” January 6th 2026 at 12:50

Order and contact details accessed via ecommerce partner, and phishing has begun

Blockchain security biz Ledger says customer information was accessed in a breach at its ecommerce payment partner Global-e, and is warning that other brands using the platform may also be affected.…

☐ β˜† βœ‡ The Register - Security

Students bag extended Christmas break after cyber hit on school IT

β€” January 6th 2026 at 10:55

Phones, email, and core systems knocked out at Higham Lane in Nuneaton

Students at a school in Warwickshire, England, have scored an extended Christmas break after a cyberattack crippled its IT systems, forcing classrooms to close and staff to summon government incident responders.…

☐ β˜† βœ‡ The Register - Security

UK injects just Β£210M into cyber plan to stop Whitehall getting pwnd

β€” January 6th 2026 at 10:37

Central government will supposedly be as secure as energy facilities and datacenters under new proposals

The UK today launches its Government Cyber Action Plan, committing Β£210 million ($282 million) to strengthen defenses across digital public services and hold itself to the same cybersecurity standards it's imposing on critical infrastructure operators.…

☐ β˜† βœ‡ The Register - Security

One criminal, 50 hacked organizations, and all because MFA wasn't turned on

β€” January 6th 2026 at 07:01

Crim used infostealer to get cloud credentials

If you don't say "yes way" to MFA, the consequences can be disastrous. Sensitive data belonging to about 50 global enterprises is listed for sale – and, in some cases, has already been sold – on the dark web following a major infostealer campaign, with apparent victims including American utility engineering firm Pickett and Associates; Japan's homebuilding giant Sekisui House; and Spain's largest airline Iberia.…

☐ β˜† βœ‡ The Register - Security

Congrats, cybercrims: You just fell into a honeypot

β€” January 5th 2026 at 20:21

A subpoena has been issued, apparently

Resecurity offered its "congratulations" to the Scattered Lapsus$ Hunters cybercrime crew for falling into its threat intel team's honeypot – resulting in a subpoena being issued for one of the data thieves. Meanwhile, the notorious extortionists have since removed their claims of gaining "full access" to the security shop's systems.…

☐ β˜† βœ‡ The Register - Security

Playing Koi: Palo Alto isn't saying if it will buy security start-up

β€” January 5th 2026 at 18:06

CEO Nikesh Arora's trip to Tel Aviv last month sparked rumors.

Palo Alto Networks is on shopping spree. The company is reportedly considering a $400 million purchase of Israeli cybersecurity start up Koi, which raised $48 million in funding last year. …

☐ β˜† βœ‡ The Register - Security

Gmail preparing to drop POP3 mail fetching

β€” January 5th 2026 at 14:10

It's January 2026, and Google is finding innovative new ways to make one of its services worse

Important news for Gmail power users: Google is dropping the feature whereby Gmail can collect mail from other email accounts over POP3.…

☐ β˜† βœ‡ The Register - Security

New Zealand orders review into ManageMyHealth cyberattack

β€” January 5th 2026 at 11:52

Government 'incredibly' concerned about breach potentially affecting more than 100,000 patients

New Zealand health minister Simeon Brown has ordered a review into the cyberattack at ManageMyHealth, which threatens the data of hundreds of thousands of Kiwis.…

☐ β˜† βœ‡ The Register - Security

Trump admin sends heart emoji to commercial spyware makers with lifted Predator sanctions

β€” January 4th 2026 at 19:02

Also, Korean Air hacked, EmEditor installer hijacked, a perfect 10 router RCE vuln, and more

infosec in brief The Trump administration has cleared a trio of individuals sanctioned by the Biden administration for involvement with the Intellexa spyware consortium behind the Predator surveillance tool, removing restrictions that had barred them from doing business with the US.…

☐ β˜† βœ‡ The Register - Security

Palo Alto Networks security-intel boss calls AI agents 2026's biggest insider threat

β€” January 4th 2026 at 10:40

Lock 'em down

interview AI agents represent the new insider threat to companies in 2026, according to Palo Alto Networks Chief Security Intel Officer Wendi Whitmore, and this poses several challenges to executives tasked with securing the expected surge in autonomous agents.…

☐ β˜† βœ‡ The Register - Security

Bitfinex crypto thief who was serving five years thanks Trump for early release

β€” January 2nd 2026 at 20:22

Netflix documentary part 2 in the works?

Ilya Lichtenstein, who pleaded guilty to money-laundering charges tied to the 2016 theft of about 120,000 bitcoins from the Bitfinex exchange and was sentenced to five years in prison, has been released after roughly 14 months in the slammer.…

☐ β˜† βœ‡ The Register - Security

Cybercrook claims to be selling infrastructure info about three major US utilities

β€” January 2nd 2026 at 18:34

For the bargain price of 6.5 bitcoin

A cybercrook claims to have breached Pickett and Associates, a Florida-based engineering firm whose clients include major US utilities, and is selling what they claim to be about 139 GB of engineering data about Tampa Electric Company, Duke Energy Florida, and American Electric Power.Β The price is 6.5 bitcoin, which amounts to about $585,000.…

☐ β˜† βœ‡ The Register - Security

Brit lands invite-only Aussie visa after uncovering vuln in government systems

β€” January 2nd 2026 at 16:11

Jacob Riggs is set to swap London for Sydney some time in the next year

A British security researcher has secured Australia's strictest, invite-only visa after discovering a critical vulnerability in a government system.…

☐ β˜† βœ‡ The Register - Security

LockBit takedown architect gets New Year award from King Charles

β€” January 2nd 2026 at 12:26

Gavin Webb orchestrated Operation Cronos as it pulled off the legendary disruption sting

A senior British crimefighter has been awarded one of the country's highest tributes for public service for his role in the 2024 LockBit ransomware takedown.…

☐ β˜† βœ‡ The Register - Security

Cisco XDR in 30: Turning Security Signals Into Confident Action

β€” January 2nd 2026 at 08:00

How network-led Cisco XDR helps teams see threats clearly and respond faster

Sponsored Post Security teams are being asked to do more with less, while the environments they protect continue to grow in size and complexity. Alerts arrive from dozens of tools, each offering a partial view of risk. The real challenge is no longer finding potential threats, but deciding which ones matter and how quickly to act.…

☐ β˜† βœ‡ The Register - Security

European Space Agency hit again as cybercrims claim 200 GB data up for sale

β€” December 31st 2025 at 16:55

As in past incidents, ESA says the impact was limited to external systems

The European Space Agency has suffered yet another security incident and, in keeping with past practice, says the impact is limited. Meanwhile, miscreants boast that they've made off with a trove of data, including what they claim are confidential documents, credentials, and source code.…

☐ β˜† βœ‡ The Register - Security

Hong Kong’s newest anti-scam technology is over-the-counter banking

β€” December 31st 2025 at 04:57

Funds in β€˜Money Safe’ accounts are only available when customers appear for face-to-face verification

Hong Kong’s banks have a new weapon against scams: Accounts that require customers to visit a branch to access their funds.…

☐ β˜† βœ‡ The Register - Security

Cybersecurity pros admit to moonlighting as ransomware scum

β€” December 31st 2025 at 01:46

Pair became ALPHV affiliates to prey on US-based clients

A ransomware negotiator and a security incident response manager have admitted to running ransomware attacks.…

☐ β˜† βœ‡ The Register - Security

New York’s incoming mayor bans Raspberry Pi at his inauguration party

β€” December 31st 2025 at 00:31

Zohran Mamdani appears not to understand that smartphones can be used for evil

New York’s mayor-elect Zohran Mamdani has invited the city’s residents to join him at a block party to celebrate his inauguration but told attendees not to bring a Raspberry Pi single-board computer to the event.…

☐ β˜† βœ‡ The Register - Security

An early end to the holidays: 'Heartbleed of MongoDB' is now under active exploit

β€” December 30th 2025 at 19:27

You didn't think you'd get to enjoy your time off without a major cybersecurity incident, did you?

A high-severity MongoDB Server vulnerability, for which proofs of concept emerged over Christmas week, is now under active exploitation, according to the US Cybersecurity and Infrastructure Security Agency.…

☐ β˜† βœ‡ The Register - Security

Korean telco failed at femtocell security, exposed customers to snooping and fraud

β€” December 30th 2025 at 03:34

One cert, in plaintext, on thousands of devices, led to what looks like years of crime

South Korea’s Ministry of Science and ICT has found that local carrier Korea Telecom (KT) deployed thousands of badly secured femtocells, leading to an attack that enabled micropayments fraud and snooping on customers’ communications – maybe for years.…

☐ β˜† βœ‡ The Register - Security

Indian cops cuff ex-Coinbase rep over selling customer info to crims

β€” December 29th 2025 at 21:16

There's more where that came from, CEO says

Rogue insiders suspected of taking bribes to hand over Coinbase customer records to criminals are beginning to face justice, according to CEO Brian Armstrong.…

☐ β˜† βœ‡ The Register - Security

Crims disconnect Wired subscribers from their privacy, publish deets online

β€” December 29th 2025 at 19:23

Extortion group Lovely claims to have stolen 40 million pieces of info from publisher Conde Nast

A criminal group is beating Conde Nast over the head for not responding sooner to its extortion attempt by posting stolen subscribers' email and home addresses and warning the publisher of Wired, The New Yorker, Vanity Fair, and Teen Vogue that it has 40 million more entries.…

☐ β˜† βœ‡ The Register - Security

Europe's cloud challenge: Building an Airbus for the digital age

β€” December 29th 2025 at 09:23

Countries that banded together to challenge Boeing in the air try to do the same to AWS, Microsoft, and Google on the ground

Feature More than half a century ago, a consortium of European aerospace businesses from the UK, France, Germany and Spain joined forces to take on America's Boeing. Fast forward to the 21st century and the countries are applying the same model needs to the world of cloud computing, giving the continent a fighting chance to reduce the digital domination of Big Tech.…

☐ β˜† βœ‡ The Register - Security

Accused data thief threw MacBook into a river to destroy evidence

β€” December 29th 2025 at 04:06

Former staffer of Korean e-tailer Coupang accessed 33 million records but may have done less damage than feared

Korean e-tailer Coupang claims a former employee has admitted to improperly accessing data describing 33 million of its customers, but says the accused deleted the stolen data.…

☐ β˜† βœ‡ The Register - Security

Death, torture, and amputation: How cybercrime shook the world in 2025

β€” December 28th 2025 at 14:34

The human harms of cyberattacks piled up this year, and violence expected to increase

The knock-on, and often unintentional, impacts of a cyberattack are so rarely discussed. As an industry, the focus is almost always placed on the economic damage: the ransom payment; the cost of business downtime; and goodness, don't forget those poor shareholders.…

☐ β˜† βœ‡ The Register - Security

From AI to analog, cybersecurity tabletop exercises look a little different this year

β€” December 26th 2025 at 17:01

Practice makes perfect

It's the most wonderful time of the year … for corporate security bosses to run tabletop exercises, simulating a hypothetical cyberattack or other emergency, running through incident processes, and practicing responses to ensure preparedness if when a digital disaster occurs.…

☐ β˜† βœ‡ The Register - Security

From video games to cyber defense: If you don't think like a hacker, you won't win

β€” December 26th 2025 at 15:11

In supercharged AI race, defenders need to keep up

interview According to Remedio CEO Tal Kollender, the only way to beat the bad guys hacking into corporate networks is to "think like a hacker," and because not everyone is a teenage hacker turned cybersecurity startup chief executive, she built an AI to do this.…

☐ β˜† βœ‡ The Register - Security

Pen testers accused of 'blackmail' after reporting Eurostar chatbot flaws

β€” December 24th 2025 at 18:22

AI goes off the rails … because of shoddy guardrails

Researchers at Pen Test Partners found four flaws in Eurostar's public AI chatbot that, among other security issues, could allow an attacker to inject malicious HTML content or trick the bot into leaking system prompts.Β Their thank you from the company: being accused of "blackmail."…

☐ β˜† βœ‡ The Register - Security

US shuts down phisherfolk’s $14.6M password-hoarding platform

β€” December 24th 2025 at 15:07

Crooks used platform to scoop up and store banking credentials for big-money thefts

The US says it has shut down a platform used by cybercriminals to break into Americans' bank accounts.…

☐ β˜† βœ‡ The Register - Security

Microsoft wants to replace its entire C and C++ codebase, perhaps by 2030

β€” December 24th 2025 at 03:39

Plans move to Rust, with help from AI

Microsoft wants to develop tech that could translate its codebase to Rust, and is hiring people to make it happen.…

☐ β˜† βœ‡ The Register - Security

ServiceNow opens $7.7B ticket titled 'Buy security company, make it Armis'

β€” December 23rd 2025 at 22:17

Customers will be able to see vulnerabilities, prioritize risks, and close them with automated workflows.

After over a week of speculation, ServiceNow announced on Tuesday that it has agreed to buy cybersecurity heavyweight Armis in a $7.75 billion deal that will see the workflow giant incorporate a real-time security intelligence feed into its products.…

☐ β˜† βœ‡ The Register - Security

21K Nissan customers' data stolen in Red Hat raid

β€” December 23rd 2025 at 17:23

Automaker's third security snafu in three years

Thousands of Nissan customers are learning that some of their personal data was leaked after unauthorized access to a Red Hat-managed server, according to the Japanese automaker.…

☐ β˜† βœ‡ The Register - Security

Microsoft rushes an out-of-band update for Message Queuing bug

β€” December 23rd 2025 at 16:37

Redmond gets in early for the twelve whoopsies of Christmas

Microsoft has hustled out an out-of-band update to address a Message Queuing issue introduced by the December 2025 update.…

☐ β˜† βœ‡ The Register - Security

Poisoned WhatsApp API package steals messages and accounts

β€” December 22nd 2025 at 22:04

And it's especially dangerous because the code works

A malicious npm package with more than 56,000 downloads masquerades as a working WhatsApp Web API library, and then it steals messages, harvests credentials and contacts, and hijacks users' WhatsApp accounts.…

☐ β˜† βœ‡ The Register - Security

Palo Alto's new Google Cloud deal boosts AI integration, could save on cloud costs

β€” December 22nd 2025 at 21:19

SEC filings show the outfit cut projected 2027 cloud purchase commitments by $114M

Security vendor Palo Alto Networks is expanding its Google Cloud partnership, saying it will move "key internal workloads" onto the Chocolate Factory's infrastructure. The outfit also claims it is tightening integrations between its security tools and Google Cloud to deliver what it calls a "unified" security experience. At the same time, Palo Alto may trim its own cloud purchase commitments.…

☐ β˜† βœ‡ The Register - Security

Spy turned startup CEO: 'The WannaCry of AI will happen'

β€” December 22nd 2025 at 19:39

Ah, the good old days when 0-day development took a year

Interview "In my past life, it would take us 360 days to develop an amazing zero day," Zafran Security CEO Sanaz Yashar said.…

☐ β˜† βœ‡ The Register - Security

Hacktivists scrape 86M Spotify tracks, claim their aim is to preserve culture

β€” December 22nd 2025 at 17:24

Anna’s Archive’s idealism doesn’t quite survive its own blog post

What would happen to the world's music collections if streaming services disappeared? One hacktivist group says it has a solution: scrape around 300 terabytes of music and metadata from Spotify and offer it up for free as what it calls the world’s first β€œfully open” music preservation archive.…

☐ β˜† βœ‡ The Register - Security

Conman and wannabe MI6 agent must repay Β£125k to romance scam victim

β€” December 22nd 2025 at 16:37

Judge says former most-wanted fugitive Mark Acklom will likely never return to the UK

The UK's Crown Prosecution Service (CPS) says a fraudster who claimed to be part of MI6 must repay Β£125,000 ($168,000) to a former love interest that he conned.…

☐ β˜† βœ‡ The Register - Security

Around 1,000 systems compromised in ransomware attack on Romanian water agency

β€” December 22nd 2025 at 12:13

On-site staff keep key systems working while all but one region battles with encrypted PCs

Romania's cybersecurity agency confirms a major ransomware attack on the country's water management administration has compromised around 1,000 systems, with work to remediate them still ongoing.…

☐ β˜† βœ‡ The Register - Security

There’s so much stolen data in the world, South Korea will require face scans to buy a SIM

β€” December 22nd 2025 at 04:11

SK Telecom's epic infosec fail will cost it another $1.5 billion

South Korea's government on Friday announced it will require local mobile carriers to verify the identity of new customers with facial recognition scans, in the hope of reducing scams.…

☐ β˜† βœ‡ The Register - Security

Through gritted teeth, Apple and Google allow alternative app stores in Japan

β€” December 22nd 2025 at 00:14

PLUS: Debian supports Chinese chips ; Hong Kong’s Christmas Karaoke crackdown; Asahi admits it should have prevented hack; And more!

APAC in Brief Google and Apple last week started to allow developers of mobile applications to distribute their wares through third-party app stores and accept payments from alternative payment providers.…

☐ β˜† βœ‡ The Register - Security

Google sends Dark Web Report to its dead services graveyard

β€” December 21st 2025 at 22:34

PLUS: Texas sues alleged TV spies; The Cloud is full of holes; Hospital leaked its own data; And more

Infosec In Brief Google will soon end its β€œDark Web Report”, an email service that alerts users when their personal information appears on the internet’s dark underbelly.…

☐ β˜† βœ‡ The Register - Security

NIST contemplated pulling the pin on NTP servers after blackout caused atomic clock drift

β€” December 21st 2025 at 07:40

Time signals shifted by a tiny amount that only very sensitive users would find upsetting

UPDATED A staffer at the USA’s National Institute of Standards and Technology (NIST) tried to disable some of its Network Time Protocol infrastructure, after a power outage around Boulder, Colorado, led to errors.…

❌