FreshRSS

πŸ”’
❌ Secure Planet Training Courses Updated For 2019 - Click Here
There are new available articles, click to refresh the page.
☐ β˜† βœ‡ The Register - Security

Flickr emails users about data breach, pins it on 3rd party

β€” February 6th 2026 at 16:56

Attackers may have snapped user locations and activity information, message warns

Legacy image-sharing website Flickr suffered a data breach, according to customers emails seen by The Register.…

☐ β˜† βœ‡ The Register - Security

DDoS deluge: Brit biz battered as botnet blitzes break records

β€” February 6th 2026 at 16:36

UK leaps to sixth in global flood charts as mega-swarm unleashes 31.4 Tbps Yuletide pummeling

Cloudflare says DDoS crews ended 2025 by pushing traffic floods to new extremes, while Britain made an unwelcome leap of 36 places to become the world's sixth-most targeted location.…

☐ β˜† βœ‡ The Register - Security

Ad blocking is alive and well, despite Chrome's attempts to make it harder

β€” February 6th 2026 at 00:39

The end isn't nigh after all

Chrome's latest revision of its browser extension architecture, known as Manifest v3 (MV3), was widely expected to make content blocking and privacy extensions less effective than its predecessor, Manifest v2 (MV2).…

☐ β˜† βœ‡ The Register - Security

OpenClaw reveals meaty personal information after simple cracks

β€” February 5th 2026 at 23:32

Skills marketplace is full of stuff - like API keys and credit card numbers - that crims will find tasty

Another day, another vulnerability (or two, or 200) in the security nightmare that is OpenClaw.…

☐ β˜† βœ‡ The Register - Security

Substack says intruder lifted emails, phone numbers in months-old breach

β€” February 5th 2026 at 19:54

Contact details were accessed in an intrusion that went undetected for months, the blogging outfit says

Newsletter platform Substack has admitted that an intruder swiped user contact details months before the company noticed, forcing it to warn writers and readers that their email addresses and other account metadata were accessed without permission.…

☐ β˜† βœ‡ The Register - Security

Asia-based government spies quietly broke into critical networks across 37 countries

β€” February 5th 2026 at 19:21

And their toolkit includes a new, Linux kernel rootkit

A state-aligned cyber group in Asia compromised government and critical infrastructure organizations across 37 countries in an ongoing espionage campaign, according to security researchers.…

☐ β˜† βœ‡ The Register - Security

Betterment breach may expose 1.4M users after social engineering attack

β€” February 5th 2026 at 16:25

Breach-tracking site flags dataset following impersonation-based intrusion

Breach-tracking site Have I Been Pwned (HIBP) claims a cyberattack on Betterment affected roughly 1.4 million users – although the investment company has yet to publicly confirm how many customers were affected by January's intrusion.…

☐ β˜† βœ‡ The Register - Security

Italy claims cyberattacks 'of Russian origin' are pelting Winter Olympics

β€” February 5th 2026 at 11:49

Right on cue, petulant hacktivists attempt to disrupt yet another global sporting event

Italy's foreign minister says the country has already started swatting away cyberattacks from Russia targeting the Milano Cortina Winter Olympics.…

☐ β˜† βœ‡ The Register - Security

n8n security woes roll on as new critical flaws bypass December fix

β€” February 5th 2026 at 11:38

Patch meant to close a severe expression bug fails to stop attackers with workflow access

Multiple newly disclosed bugs in the popular workflow automation tool n8n could allow attackers to hijack servers, steal credentials, and quietly disrupt AI-driven business processes.…

☐ β˜† βœ‡ The Register - Security

Cloud sovereignty is no longer just a public sector concern

β€” February 5th 2026 at 11:00

Businesses still chase the cheapest option, but politics and licensing shocks are changing priorities, says OpenNebula

Interview Sovereignty remains a hot topic in the tech industry, but interpretations of what it actually means – and how much it matters – vary widely between organizations and sectors. While public bodies are often driven by regulation and national policy, the private sector tends to take a more pragmatic, cost-focused view.…

☐ β˜† βœ‡ The Register - Security

Three clues that your LLM may be poisoned with a sleeper-agent back door

β€” February 5th 2026 at 07:32

It's a threat straight out of sci-fi, and fiendishly hard to detect

Sleeper agent-style backdoors in AI large language models pose a straight-out-of-sci-fi security threat.…

☐ β˜† βœ‡ The Register - Security

Satya Nadella decides Microsoft needs an engineering quality czar

β€” February 5th 2026 at 05:46

Picks chap who used to lead Redmond’s security, lures replacement from Google

Microsoft CEO Satya Nadella has decided Microsoft needs an engineering quality czar, and shifted Charlie Bell, the company’s executive veep for security, into the new role.…

☐ β˜† βœ‡ The Register - Security

AWS intruder achieved admin access in under 10 minutes thanks to AI assist, researchers say

β€” February 4th 2026 at 21:09

LLMs automated most phases of the attack

UPDATED A digital intruder broke into an AWS cloud environment and in just under 10 minutes went from initial access to administrative privileges, thanks to an AI speed assist.…

☐ β˜† βœ‡ The Register - Security

Critical SolarWinds Web Help Desk bug under attack

β€” February 4th 2026 at 18:15

US agencies told to patch by Friday

Attackers are exploiting a critical SolarWinds Web Help Desk bug - less than a week after the vendor disclosed and fixed the 9.8-rated flaw. That's according to America's lead cyber-defense agency, which set a Friday deadline for federal agencies to patch the security flaw.…

☐ β˜† βœ‡ The Register - Security

Nitrogen ransomware is so broken even the crooks can't unlock your files

β€” February 4th 2026 at 13:50

Gang walks away with nothing, victims are left with irreparable hypervisors

Cybersecurity experts usually advise victims against paying ransomware crooks, but that advice goes double for those who have been targeted by the Nitrogen group. There's no way to get your data back from them!…

☐ β˜† βœ‡ The Register - Security

Universal Β£7,500 payout offered to PSNI staff over major data breach

β€” February 4th 2026 at 11:41

Affected police officers squeezed mental health services, relocated over safety fears

Police Service of Northern Ireland (PSNI) employees who had their details exposed in a significant 2023 data breach will each receive Β£7,500 ($10,279) as part of a universal offer of compensation.…

☐ β˜† βœ‡ The Register - Security

Clouds rush to deliver OpenClaw-as-a-service offerings

β€” February 4th 2026 at 05:28

As analyst house Gartner declares AI tool β€˜comes with unacceptable cybersecurity risk’ and urges admins to snuff it out

If you’re brave enough to want to run the demonstrably insecure AI assistant OpenClaw, several clouds have already started offering it as a service.…

☐ β˜† βœ‡ The Register - Security

AI agents can't yet pull off fully autonomous cyberattacks – but they are already very helpful to crims

β€” February 3rd 2026 at 23:57

Don't relax: This is a 'when, not if' scenario

AI agents and other systems can't yet conduct cyberattacks fully on their own – but they can help criminals in many stages of the attack chain, according to the International AI Safety report.…

☐ β˜† βœ‡ The Register - Security

Critical React Native Metro dev server bug under attack as researchers scream into the void

β€” February 3rd 2026 at 19:01

Too slow react-ion time

Baddies are exploiting a critical bug in React Native's Metro development server to deliver malware to both Windows and Linux machines, and yet the in-the-wild attacks still haven't received the "broad public acknowledgement" that they should, according to security researchers.…

☐ β˜† βœ‡ The Register - Security

CISA updated ransomware intel on 59 bugs last year without telling defenders

β€” February 3rd 2026 at 17:17

GreyNoise's Glenn Thorpe counts the cost of missed opportunities

On 59 occasions throughout 2025, the US Cybersecurity and Infrastructure Security Agency (CISA) silently tweaked vulnerability notices to reflect their use by ransomware crooks. Experts say that's a problem.…

☐ β˜† βœ‡ The Register - Security

X marks the raid: French cops swoop on Musk's Paris ops

β€” February 3rd 2026 at 13:09

Algorithmic bias probe continues, CEO and former boss summoned to defend the platform's corner

French police raided Elon Musk's X offices in Paris this morning as part of a criminal investigation into alleged algorithmic manipulation by foreign powers.…

☐ β˜† βœ‡ The Register - Security

Microsoft finally sends TLS 1.0 and 1.1 to the cloud retirement home

β€” February 3rd 2026 at 12:59

Azure Storage now requires version 1.2 or newer for encrypted connections

Today is the day Azure Storage stops supporting versions 1.0 and 1.1 of Transport Layer Security (TLS). TLS 1.2 is the new minimum.…

☐ β˜† βœ‡ The Register - Security

Polish cops bail 20-year-old bedroom botnet operator

β€” February 3rd 2026 at 12:34

DDoSer of 'strategically important' websites admitted to most charges

Polish authorities have cuffed a 20-year-old man on suspicion of carrying out DDoS attacks.…

☐ β˜† βœ‡ The Register - Security

DIY AI bot farm OpenClaw is a security 'dumpster fire'

β€” February 3rd 2026 at 10:14

Your own personal Jarvis. A bot to hear your prayers. A bot that cares. Just not about keeping you safe

OpenClaw, the AI-powered personal assistant users interact with via messaging apps and sometimes entrust with their credentials to various online services, has prompted a wave of malware and is delivering some shocking bills.…

☐ β˜† βœ‡ The Register - Security

British military to get legal OK to swat drones near bases

β€” February 3rd 2026 at 09:30

Armed Forces Bill would let troops take action against unmanned threats around defense sites

Britain's defense personnel will be given the authority to neutralize drones threatening military bases under measures being introduced in the Armed Forces Bill, currently making its way through Parliament.…

☐ β˜† βœ‡ The Register - Security

Notepad++ hijacking blamed on Chinese Lotus Blossom crew behind Chrysalis backdoor

β€” February 2nd 2026 at 23:23

The group targets telecoms, critical infrastructure - all the usual high-value orgs

Security researchers have attributed the Notepad++ update hijacking to a Chinese government-linked espionage crew called Lotus Blossom (aka Lotus Panda, Billbug), which abused weaknesses in the update infrastructure to gain a foothold in high-value targets by delivering a newly identified backdoor dubbed Chrysalis.…

☐ β˜† βœ‡ The Register - Security

StopICE hacked to send alarming text messages, admins accuse border patrol agent of sabotage

β€” February 2nd 2026 at 19:16

The ICE-tracking service says it doesn't store usernames or addresses

ICE-reporting service StopICE has blamed a US Customs and Border Protection (CBP) agent for attacking its app and website and sending users text messages warning them that their information had been "sent to the authorities."…

☐ β˜† βœ‡ The Register - Security

Russia-linked APT28 attackers already abusing new Microsoft Office zero-day

β€” February 2nd 2026 at 18:18

Ukraine’s CERT says the bug went from disclosure to active exploitation in days

Russia-linked attackers are already exploiting Microsoft's latest Office zero-day, with Ukraine's national cyber defense team warning that the same bug is being used to target government agencies inside the country and organizations across the EU.…

☐ β˜† βœ‡ The Register - Security

McDonald's is not lovin' your bigmac, happymeal, and mcnuggets passwords

β€” February 2nd 2026 at 17:05

Your favorite menu item might be easy to remember but it will not secure your account

Change Your Password Day took place over the weekend, and in case you doubt the need to improve this most basic element of cybersecurity hygiene, even McDonald's – yes, the fast food chain – is urging people to get more creative when it comes to passwords. …

☐ β˜† βœ‡ The Register - Security

OpenClaw patches one-click RCE as security Whac-A-Mole continues

β€” February 2nd 2026 at 14:10

Researchers disclose rapid exploit chain that let attackers run code via a single malicious web page

Security issues continue to pervade the OpenClaw ecosystem, formerly known as ClawdBot then Moltbot, as multiple projects patch bot takeover and remote code execution (RCE) exploits.…

☐ β˜† βœ‡ The Register - Security

Notepad++ update service hijacked in targeted state-linked attack

β€” February 2nd 2026 at 13:19

Breach lingered for months before stronger signature checks shut the door

A state-sponsored cyber criminal compromised Notepad++'s update service in 2025, according to the project's author.…

☐ β˜† βœ‡ The Register - Security

Infrastructure cyberattacks are suddenly in fashion. We can buck the trend

β€” February 2nd 2026 at 10:15

Don't be scared of the digital dark – learn how to keep the lights on

Opinion Barely a month into 2026, electrical power infrastructure on two continents has tested positive for cyberattacks. One fell flat as attempts to infiltrate and disrupt the Polish distribution grid were rebuffed and reported. The other, earlier attack was part of Operation Absolute Resolve, the US abduction of Venezuela's President Maduro from Caracas on January 3.…

☐ β˜† βœ‡ The Register - Security

Why native cloud security falls short

β€” February 2nd 2026 at 08:00

Your cloud security must stand alone

Partner Content As cloud adoption accelerates, many organizations are increasingly relying on the native security features offered by cloud service providers (CSPs). The ability to manage web application firewalls (WAF), data encryption, and key management (KMS) within a single provider ecosystem appears efficient and convenient. However, when security and reliability are viewed through the lens of enterprise risk management, this convenience may come at a significant cost.…

☐ β˜† βœ‡ The Register - Security

Open-source AI is a global security nightmare waiting to happen, say researchers

β€” February 1st 2026 at 23:40

Also, South Korea gets a pentesting F, US Treasury says bye bye to BAH, North Korean hackers evolve, and more

Infosec in Brief As if AI weren't enough of a security concern, now researchers have discovered that open-source AI deployments may be an even bigger problem than those from commercial providers. …

☐ β˜† βœ‡ The Register - Security

AI security startup CEO posts a job. Deepfake candidate applies, inner turmoil ensues.

β€” February 1st 2026 at 14:14

'I did not think it was going to happen to me, but here we are'

Nearly every company, from tech giants like Amazon to small startups, has first-hand experience with fake IT workers applying for jobs - and sometimes even being hired. …

☐ β˜† βœ‡ The Register - Security

January blues return as Ivanti coughs up exploited EPMM zero-days

β€” January 30th 2026 at 22:01

Consider yourselves compromised, experts warn

Ivanti has patched two critical zero-day vulnerabilities in its Endpoint Manager Mobile (EPMM) product that are already being exploited, continuing a grim run of January security incidents for enterprise IT vendors.…

☐ β˜† βœ‡ The Register - Security

Thousands more Oregon residents learn their health data was stolen in TriZetto breach

β€” January 30th 2026 at 18:32

Parent company Cognizant hit with multiple lawsuits

Thousands more Oregonians will soon receive data breach letters in the continued fallout from the TriZetto data breach, in which someone hacked the insurance verification provider and gained access to its healthcare provider customers across multiple US states.…

☐ β˜† βœ‡ The Register - Security

Java developers want container security, just not the job that comes with it

β€” January 30th 2026 at 00:12

BellSoft survey finds 48% prefer pre‑hardened images over managing vulnerabilities themselves

Java developers still struggle to secure containers, with nearly half (48 percent) saying they'd rather delegate security to providers of hardened containers than worry about making their own container security decisions.…

☐ β˜† βœ‡ The Register - Security

Maybe CISA should take its own advice about insider threats hmmm?

β€” January 29th 2026 at 23:19

The call is coming from inside the house

opinion Maybe everything is all about timing, like the time (this week) America's lead cyber-defense agency sounded the alarm on insider threats after it came to light that its senior official uploaded sensitive documents to ChatGPT.…

☐ β˜† βœ‡ The Register - Security

To stop crims, Google starts dismantling residential proxy network they use to hide

β€” January 29th 2026 at 17:00

The Chocolate Factory strikes again, targeting the infrastructure attackers use to stay anonymous

Crims love to make it look like their traffic is actually coming from legit homes and businesses, and they do so by using residential proxy networks. Now, Google says it has "significantly degraded" what it believes is one of the world's largest residential proxy networks.…

☐ β˜† βœ‡ The Register - Security

AV vendor goes to war with security shop over update server scare

β€” January 29th 2026 at 16:58

eScan lawyers up after Morphisec claimed 'critical supply-chain compromise'

A spat has erupted between antivirus vendor eScan and threat intelligence outfit Morphisec over who spotted an update server incident that disrupted some eScan customers earlier this month.…

☐ β˜† βœ‡ The Register - Security

Seven habits that help security teams reduce risk without slowing delivery

β€” January 29th 2026 at 16:01

The right habits change everything

Sponsored Post Security teams are under pressure from every direction: supply chain threats are rising, regulatory expectations are tightening, and development cycles aren’t getting any slower. Yet for many organizations, the practical work of improving software security still comes down to the same challenge β€” how do you reduce exposure without constantly battling developers, delaying releases, or piling on process?

That’s where a more consistent set of habits can make a measurable difference.
Rather than treating software supply chain security as a one-off initiative, many teams are shifting toward repeatable practices they can build into everyday workflows. The goal isn’t perfection; it’s improving baseline security in ways that actually stick, across teams and tool chains.

Chainguard is hosting an upcoming webinar-style event designed to help security and engineering leaders identify the habits that matter most. The session exploresΒ seven practical approachesΒ for building more secure software pipelines, with a focus on reducing risk while keeping delivery moving.…

☐ β˜† βœ‡ The Register - Security

ShinyHunters swipes right on 10M records in alleged dating app data grab

β€” January 29th 2026 at 15:05

Extortion crew says it's found love in someone else's info as Match Group plays down the impact

ShinyHunters has added a fresh notch to its breach belt, claiming it has pinched more than 10 million records from Match Group, a US firm that owns some of the world's most widely used swipe-based dating platforms.…

☐ β˜† βœ‡ The Register - Security

Patch or perish: Vulnerability exploits now dominate intrusions

β€” January 29th 2026 at 13:53

Apply fixes within a few hours or face the music, say the pros

What good is a fix if you don't use it? Experts are urging security teams to patch promptly as vulnerability exploits now account for the majority of intrusions, according to the latest figures.…

☐ β˜† βœ‡ The Register - Security

Cyberattack on Poland's power grid could have turned deadly in winter cold

β€” January 29th 2026 at 12:10

Close call after an apparently deliberate attempt to starve a country of energy at the worst time

Cybersecurity experts involved in the cleanup of the cyberattacks on Poland's power network say the consequences could have been lethal.…

☐ β˜† βœ‡ The Register - Security

Ransomware crims forced to take off-RAMP as FBI seizes forum

β€” January 28th 2026 at 21:26

Cybercrime solved. The end

Ransomware crims have just lost one of their best business platforms. US law enforcement has seized the notorious RAMP cybercrime forum's dark web and clearnet domains.…

☐ β˜† βœ‡ The Register - Security

Everybody is WinRAR phishing, dropping RATs as fast as lightning

β€” January 28th 2026 at 18:59

Russians, Chinese spies, run-of-the-mill crims …

Come one, come all. Everyone from Russian and Chinese government goons to financially motivated miscreants is exploiting a long-since-patched WinRAR vuln to bring you infostealers and Remote Access Trojans (RATs).…

☐ β˜† βœ‡ The Register - Security

Fortinet unearths another critical bug as SSO accounts borked post-patch

β€” January 28th 2026 at 16:30

More work for admins on the cards as they await a full dump of fixes

Things aren't over yet for Fortinet customers – the security shop has disclosed yet another critical FortiCloud SSO vulnerability.…

☐ β˜† βœ‡ The Register - Security

Old Windows quirks help punch through new admin defenses

β€” January 28th 2026 at 13:16

Google researcher sits on UAC bypass for ages, only for it to become valid with new security feature

Microsoft patched a bevy of bugs that allowed bypasses of Windows Administrator Protection before the feature was made available earlier this month.…

☐ β˜† βœ‡ The Register - Security

Paranoid WhatsApp users rejoice: Encrypted app gets one-click privacy toggle

β€” January 27th 2026 at 22:15

Meta also replaces a legacy C++ media-handling security library with Rust

Users of Meta's WhatsApp messenger looking to simplify the process of protecting themselves are in luck, as the company is rolling out a new feature that combines multiple security settings under a single, toggleable option. …

☐ β˜† βœ‡ The Register - Security

Let them eat sourdough: ShinyHunters claims Panera Bread as stolen credentials victim

β€” January 27th 2026 at 19:49

Plus, the gang says it got in via Microsoft Entra SSO

ShinyHunters says it stole several slices of data from Panera Bread, but that's just the yeast of everyone's problems. The extortionist gang also claims to have stolen data from CarMax and Edmunds, in addition to three other organizations it posted to its blog last week.…

☐ β˜† βœ‡ The Register - Security

China-linked group accused of spying on phones of UK prime ministers' aides – for years

β€” January 27th 2026 at 15:50

Reports say Salt Typhoon attackers accessed handsets of senior govt folk

Chinese state-linked hackers are accused of spending years inside the phones of senior Downing Street officials, exposing private communications at the heart of the UK government.…

☐ β˜† βœ‡ The Register - Security

France to replace US videoconferencing wares with unfortunately named sovereign alternative

β€” January 27th 2026 at 13:11

French govt says state-run service 'Visio'Β will be more secure. Now where have we heard that name before?

France has officially told Zoom, Teams, and the rest of the US videoconferencing herd to take a hike in favor of its own homegrown app.…

☐ β˜† βœ‡ The Register - Security

Microsoft illegally installed cookies on schoolkid's tech, data protection ruling finds

β€” January 27th 2026 at 12:21

Austrian education ministry unaware of tracking software until campaigners launched case

Updated Microsoft illegally installed cookies on a school pupil's devices without consent, according to a ruling by the Austrian data protection authority (DSB).…

☐ β˜† βœ‡ The Register - Security

High Court to grill London cops over live facial recognition creep

β€” January 27th 2026 at 11:24

Victim and Big Brother Watch will argue the Met's policies are incompatible with human rights law

The High Court will hear from privacy campaigners this week who want to reshape the way the Metropolitan Police is allowed to use live facial recognition (LFR) tech.…

☐ β˜† βœ‡ The Register - Security

Office zero-day exploited in the wild forces Microsoft OOB patch

β€” January 27th 2026 at 10:35

Another actively abused Office bug, another emergency patch – Office 2016 and 2019 users are left with registry tweaks instead of fixes.

Updated Microsoft has issued an emergency Office patch after confirming a zero-day flaw is already being used in real world attacks.…

☐ β˜† βœ‡ The Register - Security

Canva among ~100 targets of ShinyHunters Okta identity-theft campaign

β€” January 26th 2026 at 22:33

Atlassian, RingCentral, ZoomInfo also among tech targets

ShinyHunters has targeted around 100 organizations in its latest Okta single sign-on (SSO) credential stealing campaign, according to researchers and the criminal group itself.…

☐ β˜† βœ‡ The Register - Security

EU looking into Elon Musk's X after Grok produces deepfake sex images

β€” January 26th 2026 at 13:17

Probe follows outcry over use of creepy image generation tool

The European Commission has launched an investigation into X amid concerns that its GenAI model Grok offered users the ability to generate sexually explicit imagery, including sexualized images of children.…

☐ β˜† βœ‡ The Register - Security

Data thieves borrow Nike's 'Just Do It' mantra, claim they ran off with 1.4TB

β€” January 26th 2026 at 12:24

US sports brand launches probe after extortion crew WorldLeaks claims it stole huge dataset

Nike says it is probing a possible breach after extortion crew WorldLeaks claimed to have lifted 1.4TB of internal data from the sportswear giant and posted samples on its leak site.…

☐ β˜† βœ‡ The Register - Security

Moscow likely behind wiper attack on Poland’s power grid, experts say

β€” January 26th 2026 at 11:54

Cyber sleuths believe Sandworm up to its old tricks with a brand-new sabotage toy

Russia was probably behind the failed attempts to compromise the systems of Poland's power companies in December, cybersecurity researchers claim.…

❌