FreshRSS

πŸ”’
❌ Secure Planet Training Courses Updated For 2019 - Click Here
There are new available articles, click to refresh the page.
☐ β˜† βœ‡ The Register - Security

AI coding assistant Cline compromised to create more OpenClaw chaos

β€” February 20th 2026 at 20:05

4K unintended installs in very odd supply chain attack

Someone compromised open source AI coding assistant Cline CLI's npm package earlier this week in an odd supply chain attack that secretly installed OpenClaw on developers' machines without their knowledge. …

☐ β˜† βœ‡ The Register - Security

ShinyHunters demands $1.5M not to leak Vegas casino and resort chain data

β€” February 20th 2026 at 18:27

What happens in Vegas…

Las Vegas hotel and casino giant Wynn Resorts appears to be the latest victim of data-grabbing and extortion gang ShinyHunters.…

☐ β˜† βœ‡ The Register - Security

Ukrainian gets five years for helping North Koreans secure US tech jobs

β€” February 20th 2026 at 14:30

Polish arrest leads to extradition and federal prison sentence

Ukrainian national Oleksandr Didenko will spend the next five years behind bars in the US for his involvement in helping North Korean IT workers secure fraudulent employment.…

☐ β˜† βœ‡ The Register - Security

Founder ditches AWS for Euro stack, finds sovereignty isn't plug-and-play

β€” February 20th 2026 at 14:06

Attempt to go 'Made in EU' offers big tech escapees a reality check where lower cloud bills come with higher effort

Building a startup entirely on European infrastructure sounds like a nice sovereignty flex right up until you actually try it and realize the real price gets paid in time, tinkering, and slowly unlearning a decade of GitHub muscle memory.…

☐ β˜† βœ‡ The Register - Security

CISA gives federal agencies three days to patch actively exploited Dell bug

β€” February 20th 2026 at 12:13

Hardcoded credential flaw in RecoverPoint already abused in espionage campaign

Uncle Sam's cyber defenders have given federal agencies just three days to patch a maximum-severity Dell bug that's been under active exploitation since at least mid-2024.…

☐ β˜† βœ‡ The Register - Security

Ex-Google engineers accused of helping themselves to chip security secrets

β€” February 20th 2026 at 10:45

Feds say trio conspired to siphon processor and cryptography IP, allegedly routing some data overseas

Two former Google engineers and a third alleged accomplice are facing federal charges after prosecutors accused them of swiping sensitive chip and security technology secrets and then trying to cover their tracks when the scheme began to unravel.…

☐ β˜† βœ‡ The Register - Security

Attackers have 16-digit card numbers, expiry dates, but not names. Now org gets Β£500k fine

β€” February 20th 2026 at 10:25

Appeals judge overrules lower tribunal in latest battle of ICO against a breached retail giant

The UK's data protection watchdog has scored a small win in a lengthy legal battle against a British retail group that lost millions of data records during a 2017 breach.…

☐ β˜† βœ‡ The Register - Security

Snyk CEO bails, wants someone with more AI experience to replace him

β€” February 20th 2026 at 05:07

Skill at buzzword bingo also required as company seeks innovative and disruptive visionary

The CEO of code review platform provider Snyk has announced he will stand down so the company can find someone better-equipped to steer the company into the age of AI.…

☐ β˜† βœ‡ The Register - Security

AI agents abound, unbound by rules or safety disclosures

β€” February 20th 2026 at 01:01

MIT CSAIL's 2025 AI Agent Index puts opaque automated systems under the microscope

AI agents are becoming more common and more capable, without consensus or standards on how they should behave, say academic researchers.…

☐ β˜† βœ‡ The Register - Security

Crims create fake remote management vendor that actually sells a RAT

β€” February 19th 2026 at 23:46

$300 a month buys you a backdoor that looks like legit software

Researchers at Proofpoint late last month uncovered what they describe as a "weird twist" on the growing trend of criminals abusing remote monitoring and management software (RMM) as their preferred attack tools.…

☐ β˜† βœ‡ The Register - Security

Crims hit a $20M jackpot via malware-stuffed ATMs

β€” February 19th 2026 at 18:39

FBI warns these cyber-physical attacks are on the rise

Thieves stole more than $20 million from compromised ATMs last year using a malware-assisted technique that the FBI says is on the uptick across the United States.…

☐ β˜† βœ‡ The Register - Security

Android malware taps Gemini to navigate infected devices

β€” February 19th 2026 at 16:04

For now, it might not function outside of a lab

Cybersecurity researchers say they've spotted the first Android malware strain that uses generative AI to improve performance once installed. But it may be only a proof of concept.…

☐ β˜† βœ‡ The Register - Security

DEF CON bans three Epstein-linked men from future events

β€” February 19th 2026 at 13:23

Emails show all discussed networking and biz interests with the sex offender throughout the 2010s

Cybersecurity conference DEF CON has added three men named in the Epstein files to its list of banned individuals. They are not accused of any criminal wrongdoing.…

☐ β˜† βœ‡ The Register - Security

UK to demand social platforms take down abusive intimate images within 48 hours

β€” February 19th 2026 at 11:32

'Why not 12?' says lawyer

The UK is bracketing "intimate images shared without a victim's consent" along with terror and child sexual abuse material, and demanding that online platforms remove them within two days.…

☐ β˜† βœ‡ The Register - Security

Healthcare security: Write login details on whiteboard, hope for the best

β€” February 19th 2026 at 11:14

You told me not to write it on a Post-it...

Bork!Bork!Bork! Today's bork is entirely human-generated and will send a shiver down the spine of security pros. No matter how secure a system is, a user's ability to undo an administrator's best efforts should not be underestimated.…

☐ β˜† βœ‡ The Register - Security

Poland bans camera-packing cars made in China from military bases

β€” February 19th 2026 at 05:55

Dell, however, is welcome to help build a local-language LLM

Poland’s Ministry of Defence has banned Chinese cars – and any others include tech to record position, images, or sound – from entering protected military facilities.…

☐ β˜† βœ‡ The Register - Security

Adidas investigates third-party data breach after criminals claim they pwned the sportswear giant

β€” February 18th 2026 at 23:57

'Potential data protection incident' at an 'independent licensing partner,' we're told

Adidas has confirmed it is investigating a third-party breach at one of its partner companies after digital thieves claimed they stole information and technical data from the German sportswear giant.…

☐ β˜† βœ‡ The Register - Security

ShinyHunters claims it drove off with 1.7M CarGurus records

β€” February 18th 2026 at 20:40

Latest in a rash of grab-and-leak data incidents

updated CarGurus purportedly suffered a data breach with 1.7 million corporate records stolen, according to a notorious cybercrime crew that posted the online vehicle marketplace on itsΒ leak site on Wednesday.…

☐ β˜† βœ‡ The Register - Security

Fraudster hacked hotel system, paid 1 cent for luxury rooms, Spanish cops say

β€” February 18th 2026 at 18:31

'First time we have detected a crime using this method,' cops say

Spanish police arrested a hacker who allegedly manipulated a hotel booking website, allowing him to pay one cent for luxury hotel stays. He also raided the mini-bars and didn't settle some of those tabs, police say.…

☐ β˜† βœ‡ The Register - Security

Texas sues TP-Link over China links and security vulnerabilities

β€” February 18th 2026 at 17:29

State disputes the company's claim that its routers are made in Vietnam

TP-Link is facing legal action from the state of Texas for allegedly misleading consumers with "Made in Vietnam" claims despite China-dominated manufacturing and supply chains, and for marketing its devices as secure despite reported firmware vulnerabilities exploited by Chinese state-sponsored actors.…

☐ β˜† βœ‡ The Register - Security

Deutsche Bahn back on track after DDoS yanks the brakes

β€” February 18th 2026 at 16:36

National rail bookings and timetables disrupted for nearly 24 hours

If you wanted to book a train trip in Germany recently, you would have been out of luck. The country's national rail company says that its services were disrupted for hours because of a cyberattack.…

☐ β˜† βœ‡ The Register - Security

Your AI-generated password isn't random, it just looks that way

β€” February 18th 2026 at 14:06

Seemingly complex strings are actually highly predictable, crackable within hours

Generative AI tools are surprisingly poor at suggesting strong passwords, experts say.…

☐ β˜† βœ‡ The Register - Security

Notepad++ declares hardened update process 'effectively unexploitable'

β€” February 18th 2026 at 12:41

Miscreants will need to find another avenue for malware shenanigans

Notepad++ has continued beefing up security with a release the project's author claims makes the "update process robust and effectively unexploitable."…

☐ β˜† βœ‡ The Register - Security

You can jailbreak an F-35 just like an iPhone, says Dutch defense chief

β€” February 18th 2026 at 12:11

No worries if the US doesn't want to be friends with Europe anymore

Lockheed Martin's F-35 fighter aircraft can be jailbroken "just like an iPhone," the Netherlands' defense secretary has claimed.…

☐ β˜† βœ‡ The Register - Security

HackerOne 'updating' Ts&Cs after bug hunters question if they're training AI

β€” February 18th 2026 at 11:00

CEO lauds security researchers, insists they're not 'inputs'

HackerOne has clarified its stance on GenAI after researchers fretted their submissions were being used to train its models.…

☐ β˜† βœ‡ The Register - Security

Palo Alto CEO says AI isn’t great for business, yet

β€” February 18th 2026 at 04:52

Sees little enterprise AI adoption other than coding assistants, buys Koi for what comes next

If enterprises are implementing AI, they’re not showing it to Palo Alto Networks CEO Nikesh Arora, who on Tuesday said business adoption of the tech lags consumer take-up by at least a couple of years – except for coding assistants.…

☐ β˜† βœ‡ The Register - Security

China-linked snoops have been exploiting Dell 0-day since mid-2024, using 'ghost NICs' to avoid detection

β€” February 18th 2026 at 00:05

Full scale of infections remains 'unknown'

China-linked attackers exploited a maximum-severity hardcoded-credential bug in Dell RecoverPoint for Virtual Machines as a zero-day since at least mid-2024. It's all part of a long-running effort to backdoor infected machines for long-term access, according to Google's Mandiant incident response team.…

☐ β˜† βœ‡ The Register - Security

China remains embedded in US energy networks 'for the purpose of taking it down'

β€” February 17th 2026 at 21:45

Plus 3 new goon squads targeted critical infrastructure last year

Three new threat groups began targeting critical infrastructure last year, while a well-known Beijing-backed crew - Volt Typhoon - continued to compromise cellular gateways and routers, and then break into US electric, oil, and gas companies in 2025, according to Dragos' annual threat report published on Tuesday.…

☐ β˜† βœ‡ The Register - Security

US lawyers fire up privacy class action accusing Lenovo of bulk data transfers to China

β€” February 17th 2026 at 13:42

Keep behavioral tracking American? PC giant says the claim is 'false'

A US law firm has accused Lenovo of violating Justice Department strictures about the bulk transfer of data to foreign adversaries, namely China.…

☐ β˜† βœ‡ The Register - Security

Polish cops nab 47-year-old man in Phobos ransomware raid

β€” February 17th 2026 at 13:14

Police say seized kit contained logins, passwords, and server IP addresses

Polish police have arrested and charged a man over ties to the Phobos ransomware group following a property raid.…

☐ β˜† βœ‡ The Register - Security

UK.gov launches cyber 'lockdown' campaign as 80% of orgs still leave door open

β€” February 17th 2026 at 11:30

Digital burglaries remain routine, and data shows most corps still don't stick to basic infosec standards

Britain is telling businesses to "lock the door" on cybercrims as new government data suggests most still haven't even found the latch.…

☐ β˜† βœ‡ The Register - Security

Ireland joins regulator smackdown after X's Grok AI accused of undressing people

β€” February 17th 2026 at 11:08

Social media platform’s legal eagles prepare to fight ever-growing number of countries

The Irish Data Protection Commission (DPC) is the latest regulator to open an investigation into Elon Musk's X following repeated reports of harmful image generation by the platform's Grok AI chatbot.…

☐ β˜† βœ‡ The Register - Security

MoD ticks shopping list as PM considers weapons budget boost

β€” February 17th 2026 at 09:14

Top brass splash cash on acoustic targeting, hypersonic missiles…and Red Hat

Keir Starmer could ramp up the UK's defense spending plans faster than planned as the MoD reeled off new purchases for Britain's armed forces.…

☐ β˜† βœ‡ The Register - Security

Canada Goose ruffles feathers over 600K record dump, says leak is old news

β€” February 16th 2026 at 18:01

Fashion brand latest to succumb to ShinyHunters' tricks

Canada Goose says an advertised breach of 600,000 records is an old raid and there are no signs of a recent compromise.…

☐ β˜† βœ‡ The Register - Security

Dutch cops arrest man after sending him confidential files by mistake

β€” February 16th 2026 at 17:26

Bungled link handed over sensitive docs, and when recipient didn't cooperate, police opted for cuffs

Dutch police have arrested a man for "computer hacking" after accidentally handing him their own sensitive files and then getting annoyed when he didn't hand them back.…

☐ β˜† βœ‡ The Register - Security

You probably can't trust your password manager if it's compromised

β€” February 16th 2026 at 16:20

Researchers demo weaknesses affecting some of the most popular options

Academics say they found a series of flaws affecting three popular password managers, all of which claim to protect user credentials in the event that their servers are compromised.…

☐ β˜† βœ‡ The Register - Security

Open source registries don't have enough money to implement basic security

β€” February 16th 2026 at 15:00

Free beer is great. Securing the keg costs money

fosdem 2026 Open source registries are in financial peril, a co-founder of an open source security foundation warned after inspecting their books. And it's not just the bandwidth costs that are killing them.…

☐ β˜† βœ‡ The Register - Security

Google patches Chrome zero-day as in-the-wild exploits surface

β€” February 16th 2026 at 12:39

High-severity CSS flaw let malicious webpages run code inside the sandbox

Google has quietly pushed out an emergency Chrome fix after attackers were caught exploiting the browser's first reported zero-day of 2026.…

☐ β˜† βœ‡ The Register - Security

US appears open to reversing some China tech bans

β€” February 16th 2026 at 04:35

PLUS: India demands two-hour deepfake takedowns; Singapore embraces AI; Japanese robot wolf gets cuddly; And more

Asia In Brief The United States may be about to change its policies regarding Chinese technology companies.…

☐ β˜† βœ‡ The Register - Security

Infosec exec sold eight zero-day exploit kits to Russia, says DoJ

β€” February 15th 2026 at 23:22

PLUS: Fake ransomware group exposed; EC blesses Google's big Wiz deal; Alleged sewage hacker cuffed; And more

Infosec in Brief The former General Manager of defense contractor L3Harris’s cyber subsidiary Trenchant sold eight zero-day exploit kits to Russia, according to a court filing last week.…

☐ β˜† βœ‡ The Register - Security

Attackers finally get around to exploiting critical Microsoft bug from 2024

β€” February 13th 2026 at 18:45

As if admins haven't had enough to do this week

Ignore patches at your own risk. According to Uncle Sam, a SQL injection flaw in Microsoft Configuration Manager patched in October 2024 is now being actively exploited, exposing unpatched businesses and government agencies to attack.…

☐ β˜† βœ‡ The Register - Security

Top Dutch telco Odido admits 6.2M customers caught in contact system caper

β€” February 13th 2026 at 11:45

Names, addresses, bank account numbers accessed – but biz insists passwords and call data untouched

The Netherlands' largest mobile network operator (MNO) has admitted that a breach of its customer contact system may have affected around 6.2 million people.…

☐ β˜† βœ‡ The Register - Security

Enforcing piracy policy earned helpdesk worker death threats

β€” February 13th 2026 at 07:27

Years later, he read about his antagonist doing time for murder

On Call Welcome to another installment of On Call, The Register's weekly reader-contributed column that tells your tech support tales.…

☐ β˜† βœ‡ The Register - Security

30+ Chrome extensions disguised as AI chatbots steal users' API keys, emails, other sensitive data

β€” February 12th 2026 at 22:59

Are you a good bot or a bad bot?

More than 30 malicious Chrome extensions installed by at least 260,000 users purport to be helpful AI assistants, but they steal users' API keys, email messages, and other personal data. Even worse: many of these are still available on the Chrome Web Store as of this writing.…

☐ β˜† βœ‡ The Register - Security

Who's the bossware? Ransomware slingers like employee monitoring tools, too

β€” February 12th 2026 at 20:07

As if snooping on your workers wasn't bad enough

Your supervisor may like using employee monitoring apps to keep tabs on you, but crims like the snooping software even more. Threat actors are now using legit bossware to blend into corporate networks and attempt ransomware deployment.…

☐ β˜† βœ‡ The Register - Security

Apple patches decade-old iOS zero-day, possibly exploited by commercial spyware

β€” February 12th 2026 at 14:01

Flaw abused 'in an extremely sophisticated attack against specific targeted individuals'

Apple patched a zero-day vulnerability affecting every iOS version since 1.0, used in what the company calls an "extremely sophisticated attack" against targeted individuals.…

☐ β˜† βœ‡ The Register - Security

Supply chain attacks now fuel a 'self-reinforcing' cybercrime economy

β€” February 12th 2026 at 11:59

Researchers say breaches link identity abuse, SaaS compromise, and ransomware into a cascading cycle

Cybercriminals are turning supply chain attacks into an industrial-scale operation, linking breaches, credential theft, and ransomware into a "self-reinforcing" ecosystem, researchers say.…

☐ β˜† βœ‡ The Register - Security

Feeling brave? Ministry of Defence seeks Β£300K digital boss to manage Β£4.6B spend

β€” February 12th 2026 at 10:15

Whoever gets it will steer UK department's IT, AI strategy, and megabucks vendor deals

The UK Ministry of Defence (MoD) is offering between Β£270,000 to Β£300,000 for a senior digital leader who will oversee more than Β£4.6 billion in spending and more than 3,000 specialist staff.…

☐ β˜† βœ‡ The Register - Security

Google: China's APT31 used Gemini to plan cyberattacks against US orgs

β€” February 12th 2026 at 07:00

Meanwhile, IP-stealing 'distillation attacks' on the rise

A Chinese government hacking group that has been sanctioned for targeting America's critical infrastructure used Google's AI chatbot, Gemini, to auto-analyze vulnerabilities and plan cyberattacks against US organizations, the company says.…

☐ β˜† βœ‡ The Register - Security

Microsoft warns that poisoned AI buttons and links may betray your trust

β€” February 12th 2026 at 01:07

Businesses are embedding prompts that produce content they want you to read, not the stuff AI makes if left to its own devices

Amid its ongoing promotion of AI’s wonders, Microsoft has warned customers it has found many instances of a technique that manipulates the technology to produce biased advice.…

☐ β˜† βœ‡ The Register - Security

Devilish devs spawn 287 Chrome extensions to flog your browser history to data brokers

β€” February 11th 2026 at 21:23

Add-ons with 37M installs leak visited URLs to 30+ recipients, researcher says

They know where you've been and they're going to share it. A security researcher has identified 287 Chrome extensions that allegedly exfiltrate browsing history data for an estimated 37.4 million installations.…

☐ β˜† βœ‡ The Register - Security

Posting AI-generated caricatures on social media is risky, infosec killjoys warn

β€” February 11th 2026 at 18:56

The more you share online, the more you open yourself to social engineering

If you've seen the viral AI work pic trend where people are asking ChatGPT to "create a caricature of me and my job based on everything you know about me" and sharing it to social, you might think it's harmless. You'd be wrong.…

☐ β˜† βœ‡ The Register - Security

Were telcos tipped off to *that* ancient Telnet bug? Cyber pros say the signs stack up

β€” February 11th 2026 at 15:41

Curious port filtering and traffic patterns suggest advisories weren’t the earliest warning signals sent

Telcos likely received advance warning about January's critical Telnet vulnerability before its public disclosure, according to threat intelligence biz GreyNoise.…

☐ β˜† βœ‡ The Register - Security

Payroll pirates are conning help desks to steal workers' identities and redirect paychecks

β€” February 11th 2026 at 13:00

Attackers using social engineering to exploit business processes, rather than tunnelling in via tech

Exclusive When fraudsters go after people's paychecks, "every employee on earth becomes a target," according to Binary Defense security sleuth John Dwyer.…

☐ β˜† βœ‡ The Register - Security

Notepad's new Markdown powers served with a side of remote code execution

β€” February 11th 2026 at 11:31

Smug faces across all those who opposed the WordPad-ification of Microsoft's humble text editor

Just months after Microsoft added Markdown support to Notepad, researchers have found the feature can be abused to achieve remote code execution (RCE).…

☐ β˜† βœ‡ The Register - Security

Legacy systems blamed as ministers promise no repeat of Afghan breach

β€” February 11th 2026 at 09:30

UK government grilled over progress made to prevent a second life-threatening leak

Legacy IT issues are hampering key technical measures designed to prevent highly sensitive data leaks, UK government officials say.…

☐ β˜† βœ‡ The Register - Security

Microsoft's Valentine's gift to admins: 6 exploited zero-day fixes

β€” February 10th 2026 at 22:10

Roses are red, violets are blue ... now get patching

What better way to say I love you than with an update? Attackers exploited a whopping six Microsoft bugs as zero-days prior to Redmond releasing software fixes on February's Patch Tuesday.…

☐ β˜† βœ‡ The Register - Security

AI agents spill secrets just by previewing malicious links

β€” February 10th 2026 at 17:55

Zero-click prompt injection can leak data when AI agents meet messaging apps, researchers warn

AI agents can shop for you, program for you, and, if you're feeling bold, chat for you in a messaging app. But beware: attackers can use malicious prompts in chat to trick an AI agent into generating a data-leaking URL, which link previews may fetch automatically.…

☐ β˜† βœ‡ The Register - Security

Singapore spent 11 months booting China-linked snoops out of telco networks

β€” February 10th 2026 at 13:43

Operation Cyber Guardian involved 100-plus staff across government and industry

Singapore spent almost a year flushing a suspected China-linked espionage crew out of its telecom networks in what officials describe as the country's largest cyber defense operation to date.…

☐ β˜† βœ‡ The Register - Security

Nearly 17,000 Volvo staff dinged in supplier breach

β€” February 10th 2026 at 11:09

HR outsourcer Conduent confirms intruders accessed benefits-related records tied to US personnel

Nearly 17,000 Volvo employees had their personal data exposed after cybercriminals breached Conduent, an outsourcing giant that handles workforce benefits and back-office services.…

❌