FreshRSS

πŸ”’
❌ Secure Planet Training Courses Updated For 2019 - Click Here
There are new available articles, click to refresh the page.
☐ β˜† βœ‡ The Register - Security

Attackers finally get around to exploiting critical Microsoft bug from 2024

β€” February 13th 2026 at 18:45

As if admins haven't had enough to do this week

Ignore patches at your own risk. According to Uncle Sam, a SQL injection flaw in Microsoft Configuration Manager patched in October 2024 is now being actively exploited, exposing unpatched businesses and government agencies to attack.…

☐ β˜† βœ‡ The Register - Security

Top Dutch telco Odido admits 6.2M customers caught in contact system caper

β€” February 13th 2026 at 11:45

Names, addresses, bank account numbers accessed – but biz insists passwords and call data untouched

The Netherlands' largest mobile network operator (MNO) has admitted that a breach of its customer contact system may have affected around 6.2 million people.…

☐ β˜† βœ‡ The Register - Security

Enforcing piracy policy earned helpdesk worker death threats

β€” February 13th 2026 at 07:27

Years later, he read about his antagonist doing time for murder

On Call Welcome to another installment of On Call, The Register's weekly reader-contributed column that tells your tech support tales.…

☐ β˜† βœ‡ The Register - Security

30+ Chrome extensions disguised as AI chatbots steal users' API keys, emails, other sensitive data

β€” February 12th 2026 at 22:59

Are you a good bot or a bad bot?

More than 30 malicious Chrome extensions installed by at least 260,000 users purport to be helpful AI assistants, but they steal users' API keys, email messages, and other personal data. Even worse: many of these are still available on the Chrome Web Store as of this writing.…

☐ β˜† βœ‡ The Register - Security

Who's the bossware? Ransomware slingers like employee monitoring tools, too

β€” February 12th 2026 at 20:07

As if snooping on your workers wasn't bad enough

Your supervisor may like using employee monitoring apps to keep tabs on you, but crims like the snooping software even more. Threat actors are now using legit bossware to blend into corporate networks and attempt ransomware deployment.…

☐ β˜† βœ‡ The Register - Security

Apple patches decade-old iOS zero-day, possibly exploited by commercial spyware

β€” February 12th 2026 at 14:01

Flaw abused 'in an extremely sophisticated attack against specific targeted individuals'

Apple patched a zero-day vulnerability affecting every iOS version since 1.0, used in what the company calls an "extremely sophisticated attack" against targeted individuals.…

☐ β˜† βœ‡ The Register - Security

Supply chain attacks now fuel a 'self-reinforcing' cybercrime economy

β€” February 12th 2026 at 11:59

Researchers say breaches link identity abuse, SaaS compromise, and ransomware into a cascading cycle

Cybercriminals are turning supply chain attacks into an industrial-scale operation, linking breaches, credential theft, and ransomware into a "self-reinforcing" ecosystem, researchers say.…

☐ β˜† βœ‡ The Register - Security

Feeling brave? Ministry of Defence seeks Β£300K digital boss to manage Β£4.6B spend

β€” February 12th 2026 at 10:15

Whoever gets it will steer UK department's IT, AI strategy, and megabucks vendor deals

The UK Ministry of Defence (MoD) is offering between Β£270,000 to Β£300,000 for a senior digital leader who will oversee more than Β£4.6 billion in spending and more than 3,000 specialist staff.…

☐ β˜† βœ‡ The Register - Security

Google: China's APT31 used Gemini to plan cyberattacks against US orgs

β€” February 12th 2026 at 07:00

Meanwhile, IP-stealing 'distillation attacks' on the rise

A Chinese government hacking group that has been sanctioned for targeting America's critical infrastructure used Google's AI chatbot, Gemini, to auto-analyze vulnerabilities and plan cyberattacks against US organizations, the company says.…

☐ β˜† βœ‡ The Register - Security

Microsoft warns that poisoned AI buttons and links may betray your trust

β€” February 12th 2026 at 01:07

Businesses are embedding prompts that produce content they want you to read, not the stuff AI makes if left to its own devices

Amid its ongoing promotion of AI’s wonders, Microsoft has warned customers it has found many instances of a technique that manipulates the technology to produce biased advice.…

☐ β˜† βœ‡ The Register - Security

Devilish devs spawn 287 Chrome extensions to flog your browser history to data brokers

β€” February 11th 2026 at 21:23

Add-ons with 37M installs leak visited URLs to 30+ recipients, researcher says

They know where you've been and they're going to share it. A security researcher has identified 287 Chrome extensions that allegedly exfiltrate browsing history data for an estimated 37.4 million installations.…

☐ β˜† βœ‡ The Register - Security

Posting AI-generated caricatures on social media is risky, infosec killjoys warn

β€” February 11th 2026 at 18:56

The more you share online, the more you open yourself to social engineering

If you've seen the viral AI work pic trend where people are asking ChatGPT to "create a caricature of me and my job based on everything you know about me" and sharing it to social, you might think it's harmless. You'd be wrong.…

☐ β˜† βœ‡ The Register - Security

Were telcos tipped off to *that* ancient Telnet bug? Cyber pros say the signs stack up

β€” February 11th 2026 at 15:41

Curious port filtering and traffic patterns suggest advisories weren’t the earliest warning signals sent

Telcos likely received advance warning about January's critical Telnet vulnerability before its public disclosure, according to threat intelligence biz GreyNoise.…

☐ β˜† βœ‡ The Register - Security

Payroll pirates are conning help desks to steal workers' identities and redirect paychecks

β€” February 11th 2026 at 13:00

Attackers using social engineering to exploit business processes, rather than tunnelling in via tech

Exclusive When fraudsters go after people's paychecks, "every employee on earth becomes a target," according to Binary Defense security sleuth John Dwyer.…

☐ β˜† βœ‡ The Register - Security

Notepad's new Markdown powers served with a side of remote code execution

β€” February 11th 2026 at 11:31

Smug faces across all those who opposed the WordPad-ification of Microsoft's humble text editor

Just months after Microsoft added Markdown support to Notepad, researchers have found the feature can be abused to achieve remote code execution (RCE).…

☐ β˜† βœ‡ The Register - Security

Legacy systems blamed as ministers promise no repeat of Afghan breach

β€” February 11th 2026 at 09:30

UK government grilled over progress made to prevent a second life-threatening leak

Legacy IT issues are hampering key technical measures designed to prevent highly sensitive data leaks, UK government officials say.…

☐ β˜† βœ‡ The Register - Security

Microsoft's Valentine's gift to admins: 6 exploited zero-day fixes

β€” February 10th 2026 at 22:10

Roses are red, violets are blue ... now get patching

What better way to say I love you than with an update? Attackers exploited a whopping six Microsoft bugs as zero-days prior to Redmond releasing software fixes on February's Patch Tuesday.…

☐ β˜† βœ‡ The Register - Security

AI agents spill secrets just by previewing malicious links

β€” February 10th 2026 at 17:55

Zero-click prompt injection can leak data when AI agents meet messaging apps, researchers warn

AI agents can shop for you, program for you, and, if you're feeling bold, chat for you in a messaging app. But beware: attackers can use malicious prompts in chat to trick an AI agent into generating a data-leaking URL, which link previews may fetch automatically.…

☐ β˜† βœ‡ The Register - Security

Singapore spent 11 months booting China-linked snoops out of telco networks

β€” February 10th 2026 at 13:43

Operation Cyber Guardian involved 100-plus staff across government and industry

Singapore spent almost a year flushing a suspected China-linked espionage crew out of its telecom networks in what officials describe as the country's largest cyber defense operation to date.…

☐ β˜† βœ‡ The Register - Security

Nearly 17,000 Volvo staff dinged in supplier breach

β€” February 10th 2026 at 11:09

HR outsourcer Conduent confirms intruders accessed benefits-related records tied to US personnel

Nearly 17,000 Volvo employees had their personal data exposed after cybercriminals breached Conduent, an outsourcing giant that handles workforce benefits and back-office services.…

☐ β˜† βœ‡ The Register - Security

British Army splashes $86M on AI gear to speed up the battlefield kill chain

β€” February 10th 2026 at 10:00

Troops fitted with new comms kit as part of Project ASGARD

British soldiers are to get an array of AI-ready kit that should mean they don't have to wait to see the "whites of their eyes" before pulling the trigger.…

☐ β˜† βœ‡ The Register - Security

Someone's attacking SolarWinds WHD to steal high‑privilege credentials - but we don't know who or how

β€” February 9th 2026 at 21:54

So many CVEs, so little time

Digital intruders exploited buggy SolarWinds Web Help Desk (WHD) instances in December to break into victims' IT environments, move laterally, and steal high-privilege credentials, according to Microsoft researchers.…

☐ β˜† βœ‡ The Register - Security

More than 135,000 OpenClaw instances exposed to internet in latest vibe-coded disaster

β€” February 9th 2026 at 17:23

By default, the bot listens on all network interfaces, and many users never change it

It's a day with a name ending in Y, so you know what that means: Another OpenClaw cybersecurity disaster.…

☐ β˜† βœ‡ The Register - Security

Dutch data watchdog snitches on itself after getting caught in Ivanti zero-day attacks

β€” February 9th 2026 at 14:50

Staff data belonging to the regulator and judiciary's governing body accessed

The Dutch Data Protection Authority (AP) says it was one of the many organizations popped when attackers raced to exploit recent Ivanti vulnerabilities as zero-days.…

☐ β˜† βœ‡ The Register - Security

Taiwan tells Uncle Sam its chip ecosystem ain't going anywhere

β€” February 9th 2026 at 14:02

Moving 40% of semiconductor production to America is 'impossible' says vice premier

Taiwan's vice-premier has ruled out relocating 40 percent of the country's semiconductor production to the US, calling the Trump administration's goal "impossible."…

☐ β˜† βœ‡ The Register - Security

How the GNU C Compiler became the Clippy of cryptography

β€” February 9th 2026 at 12:07

Security devs forced to hide Boolean logic from overeager optimizer

FOSDEM 2026 The creators of security software have encountered an unlikely foe in their attempts to protect us: modern compilers.…

☐ β˜† βœ‡ The Register - Security

Follow the money: Switzerland remains Europe's top destination for tech pay

β€” February 9th 2026 at 11:42

Average Swiss salaries dwarf those on offer across the rest of the continent

European techies looking for the biggest payday are far better off in Switzerland than anywhere else, with average salaries eclipsing all other countries on the continent.…

☐ β˜† βœ‡ The Register - Security

European Commission probes intrusion into staff mobile management backend

β€” February 9th 2026 at 10:37

Officials explore issue affecting infrastructure after CERT-EU detected suspicious activity

Brussels is digging into a cyber break-in that targeted the European Commission's mobile device management systems, potentially giving intruders a peek inside the official phones carried by EU staff.…

☐ β˜† βœ‡ The Register - Security

Indian police commissioner wants ID cards for AI agents

β€” February 9th 2026 at 04:08

PLUS: China broadens cryptocurrency crackdown; Australian facial recognition privacy revisited; Singapore debuts electric VTOL; and more!

Asia In Brief The Commissioner of Police in the Indian city of Hyderabad, population 11 million, has called for AI agents to be issued with identity cards – or at least their digital equivalent.…

☐ β˜† βœ‡ The Register - Security

Telcos aren't saying how they fought back against China's Salt Typhoon attacks

β€” February 8th 2026 at 22:25

PLUS: OpenClaw teams with VirusTotal; Crypto kidnappings in France; Critical vulns at SmarterMail; And more

Infosec In Brief So-hot-right-now AI assistant OpenClaw, which is very much not secure right now, has teamed up with security scanning service VirusTotal.…

☐ β˜† βœ‡ The Register - Security

Study confirms experience beats youthful enthusiasm

β€” February 7th 2026 at 12:30

Research shows productivity and judgment peak decades after graduation

A growing body of research continues to show that older workers are generally more productive than younger employees.…

☐ β˜† βœ‡ The Register - Security

Flickr emails users about data breach, pins it on third party

β€” February 6th 2026 at 16:56

Attackers may have snapped user locations and activity information, message warns

Legacy image-sharing website Flickr suffered a data breach, according to customer emails seen by The Register.…

☐ β˜† βœ‡ The Register - Security

DDoS deluge: Brit biz battered as botnet blitzes break records

β€” February 6th 2026 at 16:36

UK leaps to sixth in global flood charts as mega-swarm unleashes 31.4 Tbps Yuletide pummeling

Cloudflare says DDoS crews ended 2025 by pushing traffic floods to new extremes, while Britain made an unwelcome leap of 36 places to become the world's sixth-most targeted location.…

☐ β˜† βœ‡ The Register - Security

Ad blocking is alive and well, despite Chrome's attempts to make it harder

β€” February 6th 2026 at 00:39

The end isn't nigh after all

Chrome's latest revision of its browser extension architecture, known as Manifest v3 (MV3), was widely expected to make content blocking and privacy extensions less effective than its predecessor, Manifest v2 (MV2).…

☐ β˜† βœ‡ The Register - Security

OpenClaw reveals meaty personal information after simple cracks

β€” February 5th 2026 at 23:32

Skills marketplace is full of stuff - like API keys and credit card numbers - that crims will find tasty

Another day, another vulnerability (or two, or 200) in the security nightmare that is OpenClaw.…

☐ β˜† βœ‡ The Register - Security

Substack says intruder lifted emails, phone numbers in months-old breach

β€” February 5th 2026 at 19:54

Contact details were accessed in an intrusion that went undetected for months, the blogging outfit says

Newsletter platform Substack has admitted that an intruder swiped user contact details months before the company noticed, forcing it to warn writers and readers that their email addresses and other account metadata were accessed without permission.…

☐ β˜† βœ‡ The Register - Security

Asia-based government spies quietly broke into critical networks across 37 countries

β€” February 5th 2026 at 19:21

And their toolkit includes a new, Linux kernel rootkit

A state-aligned cyber group in Asia compromised government and critical infrastructure organizations across 37 countries in an ongoing espionage campaign, according to security researchers.…

☐ β˜† βœ‡ The Register - Security

Betterment breach may expose 1.4M users after social engineering attack

β€” February 5th 2026 at 16:25

Breach-tracking site flags dataset following impersonation-based intrusion

Breach-tracking site Have I Been Pwned (HIBP) claims a cyberattack on Betterment affected roughly 1.4 million users – although the investment company has yet to publicly confirm how many customers were affected by January's intrusion.…

☐ β˜† βœ‡ The Register - Security

Italy claims cyberattacks 'of Russian origin' are pelting Winter Olympics

β€” February 5th 2026 at 11:49

Right on cue, petulant hacktivists attempt to disrupt yet another global sporting event

Italy's foreign minister says the country has already started swatting away cyberattacks from Russia targeting the Milano Cortina Winter Olympics.…

☐ β˜† βœ‡ The Register - Security

n8n security woes roll on as new critical flaws bypass December fix

β€” February 5th 2026 at 11:38

Patch meant to close a severe expression bug fails to stop attackers with workflow access

Multiple newly disclosed bugs in the popular workflow automation tool n8n could allow attackers to hijack servers, steal credentials, and quietly disrupt AI-driven business processes.…

☐ β˜† βœ‡ The Register - Security

Cloud sovereignty is no longer just a public sector concern

β€” February 5th 2026 at 11:00

Businesses still chase the cheapest option, but politics and licensing shocks are changing priorities, says OpenNebula Systems

Interview Sovereignty remains a hot topic in the tech industry, but interpretations of what it actually means – and how much it matters – vary widely between organizations and sectors. While public bodies are often driven by regulation and national policy, the private sector tends to take a more pragmatic, cost-focused view.…

☐ β˜† βœ‡ The Register - Security

Three clues that your LLM may be poisoned with a sleeper-agent back door

β€” February 5th 2026 at 07:32

It's a threat straight out of sci-fi, and fiendishly hard to detect

Sleeper agent-style backdoors in AI large language models pose a straight-out-of-sci-fi security threat.…

☐ β˜† βœ‡ The Register - Security

Satya Nadella decides Microsoft needs an engineering quality czar

β€” February 5th 2026 at 05:46

Picks chap who used to lead Redmond’s security, lures replacement from Google

Microsoft CEO Satya Nadella has decided Microsoft needs an engineering quality czar, and shifted Charlie Bell, the company’s executive veep for security, into the new role.…

☐ β˜† βœ‡ The Register - Security

AWS intruder achieved admin access in under 10 minutes thanks to AI assist, researchers say

β€” February 4th 2026 at 21:09

LLMs automated most phases of the attack

UPDATED A digital intruder broke into an AWS cloud environment and in just under 10 minutes went from initial access to administrative privileges, thanks to an AI speed assist.…

☐ β˜† βœ‡ The Register - Security

Critical SolarWinds Web Help Desk bug under attack

β€” February 4th 2026 at 18:15

US agencies told to patch by Friday

Attackers are exploiting a critical SolarWinds Web Help Desk bug - less than a week after the vendor disclosed and fixed the 9.8-rated flaw. That's according to America's lead cyber-defense agency, which set a Friday deadline for federal agencies to patch the security flaw.…

☐ β˜† βœ‡ The Register - Security

Nitrogen ransomware is so broken even the crooks can't unlock your files

β€” February 4th 2026 at 13:50

Gang walks away with nothing, victims are left with irreparable hypervisors

Cybersecurity experts usually advise victims against paying ransomware crooks, but that advice goes double for those who have been targeted by the Nitrogen group. There's no way to get your data back from them!…

☐ β˜† βœ‡ The Register - Security

Universal Β£7,500 payout offered to PSNI staff over major data breach

β€” February 4th 2026 at 11:41

Affected police officers squeezed mental health services, relocated over safety fears

Police Service of Northern Ireland (PSNI) employees who had their details exposed in a significant 2023 data breach will each receive Β£7,500 ($10,279) as part of a universal offer of compensation.…

☐ β˜† βœ‡ The Register - Security

Clouds rush to deliver OpenClaw-as-a-service offerings

β€” February 4th 2026 at 05:28

As analyst house Gartner declares AI tool β€˜comes with unacceptable cybersecurity risk’ and urges admins to snuff it out

If you’re brave enough to want to run the demonstrably insecure AI assistant OpenClaw, several clouds have already started offering it as a service.…

☐ β˜† βœ‡ The Register - Security

AI agents can't yet pull off fully autonomous cyberattacks – but they are already very helpful to crims

β€” February 3rd 2026 at 23:57

Don't relax: This is a 'when, not if' scenario

AI agents and other systems can't yet conduct cyberattacks fully on their own – but they can help criminals in many stages of the attack chain, according to the International AI Safety report.…

☐ β˜† βœ‡ The Register - Security

Critical React Native Metro dev server bug under attack as researchers scream into the void

β€” February 3rd 2026 at 19:01

Too slow react-ion time

Baddies are exploiting a critical bug in React Native's Metro development server to deliver malware to both Windows and Linux machines, and yet the in-the-wild attacks still haven't received the "broad public acknowledgement" that they should, according to security researchers.…

☐ β˜† βœ‡ The Register - Security

CISA updated ransomware intel on 59 bugs last year without telling defenders

β€” February 3rd 2026 at 17:17

GreyNoise's Glenn Thorpe counts the cost of missed opportunities

On 59 occasions throughout 2025, the US Cybersecurity and Infrastructure Security Agency (CISA) silently tweaked vulnerability notices to reflect their use by ransomware crooks. Experts say that's a problem.…

☐ β˜† βœ‡ The Register - Security

X marks the raid: French cops swoop on Musk's Paris ops

β€” February 3rd 2026 at 13:09

Algorithmic bias probe continues, CEO and former boss summoned to defend the platform's corner

French police raided Elon Musk's X offices in Paris this morning as part of a criminal investigation into alleged algorithmic manipulation by foreign powers.…

☐ β˜† βœ‡ The Register - Security

Microsoft finally sends TLS 1.0 and 1.1 to the cloud retirement home

β€” February 3rd 2026 at 12:59

Azure Storage now requires version 1.2 or newer for encrypted connections

Today is the day Azure Storage stops supporting versions 1.0 and 1.1 of Transport Layer Security (TLS). TLS 1.2 is the new minimum.…

☐ β˜† βœ‡ The Register - Security

Polish cops bail 20-year-old bedroom botnet operator

β€” February 3rd 2026 at 12:34

DDoSer of 'strategically important' websites admitted to most charges

Polish authorities have cuffed a 20-year-old man on suspicion of carrying out DDoS attacks.…

☐ β˜† βœ‡ The Register - Security

DIY AI bot farm OpenClaw is a security 'dumpster fire'

β€” February 3rd 2026 at 10:14

Your own personal Jarvis. A bot to hear your prayers. A bot that cares. Just not about keeping you safe

OpenClaw, the AI-powered personal assistant users interact with via messaging apps and sometimes entrust with their credentials to various online services, has prompted a wave of malware and is delivering some shocking bills.…

☐ β˜† βœ‡ The Register - Security

British military to get legal OK to swat drones near bases

β€” February 3rd 2026 at 09:30

Armed Forces Bill would let troops take action against unmanned threats around defense sites

Britain's defense personnel will be given the authority to neutralize drones threatening military bases under measures being introduced in the Armed Forces Bill, currently making its way through Parliament.…

☐ β˜† βœ‡ The Register - Security

Notepad++ hijacking blamed on Chinese Lotus Blossom crew behind Chrysalis backdoor

β€” February 2nd 2026 at 23:23

The group targets telecoms, critical infrastructure - all the usual high-value orgs

Security researchers have attributed the Notepad++ update hijacking to a Chinese government-linked espionage crew called Lotus Blossom (aka Lotus Panda, Billbug), which abused weaknesses in the update infrastructure to gain a foothold in high-value targets by delivering a newly identified backdoor dubbed Chrysalis.…

☐ β˜† βœ‡ The Register - Security

StopICE hacked to send alarming text messages, admins accuse border patrol agent of sabotage

β€” February 2nd 2026 at 19:16

The ICE-tracking service says it doesn't store usernames or addresses

ICE-reporting service StopICE has blamed a US Customs and Border Protection (CBP) agent for attacking its app and website and sending users text messages warning them that their information had been "sent to the authorities."…

☐ β˜† βœ‡ The Register - Security

Russia-linked APT28 attackers already abusing new Microsoft Office zero-day

β€” February 2nd 2026 at 18:18

Ukraine’s CERT says the bug went from disclosure to active exploitation in days

Russia-linked attackers are already exploiting Microsoft's latest Office zero-day, with Ukraine's national cyber defense team warning that the same bug is being used to target government agencies inside the country and organizations across the EU.…

☐ β˜† βœ‡ The Register - Security

McDonald's is not lovin' your bigmac, happymeal, and mcnuggets passwords

β€” February 2nd 2026 at 17:05

Your favorite menu item might be easy to remember but it will not secure your account

Change Your Password Day took place over the weekend, and in case you doubt the need to improve this most basic element of cybersecurity hygiene, even McDonald's – yes, the fast food chain – is urging people to get more creative when it comes to passwords. …

❌