FreshRSS

πŸ”’
❌ Secure Planet Training Courses Updated For 2019 - Click Here
There are new available articles, click to refresh the page.
☐ β˜† βœ‡ The Register - Security

Sorry Dave, I’m afraid I can’t do that! PCs refuse to shut down after Microsoft patch

β€” January 16th 2026 at 16:44

Microsoft claims it's a Secure Launch bug

We're not saying Copilot has become sentient and decided it doesn't want to lose consciousness. But if it did, it would create Microsoft's January Patch Tuesday update, which has made it so that some PCs flat-out refuse to shut down or hibernate, no matter how many times you try.…

☐ β˜† βœ‡ The Register - Security

German cops add Black Basta boss to EU most-wanted list

β€” January 16th 2026 at 15:19

Ransomware kingpin who escaped Armenian custody is believed to be lying low back home

German cops have added Russian national Oleg Evgenievich Nefekov to their list of most-wanted criminals for his services to ransomware.…

☐ β˜† βœ‡ The Register - Security

RondoDox botnet linked to large-scale exploit of critical HPE OneView bug

β€” January 16th 2026 at 13:00

Check Point observes 40K+ attack attempts in 4 hours, with government organizations under fire

A critical HPE OneView flaw is now being exploited at scale, with Check Point tying mass, automated attacks to the RondoDox botnet.…

☐ β˜† βœ‡ The Register - Security

Bankrupt scooter startup left one private key to rule them all

β€” January 16th 2026 at 11:59

Owner reverse-engineered his ride, revealing authentication was never properly individualized

An Estonian e-scooter owner locked out of his own ride after the manufacturer went bust did what any determined engineer might do. He reverse-engineered it, and claims he ended up discovering the master key that unlocks every scooter the company ever sold.…

☐ β˜† βœ‡ The Register - Security

Probably not the best security in the world: Carlsberg wristbands spill visitor pics

β€” January 16th 2026 at 11:00

Researcher shows how anyone can access Copenhagen experience attendees' names, videos

Exclusive The Carlsberg exhibition in Copenhagen offers a bunch of fun activities, like blending your own beer, and the Danish brewer lets you relive those memories by making images available to download after the tour is over.…

☐ β˜† βœ‡ The Register - Security

Cisco finally fixes max-severity bug under active attack for weeks

β€” January 15th 2026 at 23:33

This is a threat to security - and to the weekend for some unlucky netadmins

Cisco finally delivered a fix for a maximum-severity bug in AsyncOS that has been under attack for at least a month.…

☐ β˜† βœ‡ The Register - Security

Chinese spies used Maduro's capture as a lure to phish US govt agencies

β€” January 15th 2026 at 22:15

What's next for Venezuela? Click on the file and see

What policy wonk wouldn't want to click on an attachment promising to unveil US plans for Venezuela? Chinese cyberspies used just such a lure to target US government agencies and policy-related organizations in a phishing campaign that began just days after an American military operation captured Venezuelan President NicolΓ‘s Maduro.…

☐ β˜† βœ‡ The Register - Security

Flipping one bit leaves AMD CPUs open to VM vuln

β€” January 15th 2026 at 21:11

Fix landed in July, but OEM firmware updates are required

If you use virtual machines, there's reason to feel less-than-Zen about AMD's CPUs. Computer scientists affiliated with the CISPA Helmholtz Center for Information Security in Germany have found a vulnerability in AMD CPUs that exposes secrets in its secure virtualization environment.…

☐ β˜† βœ‡ The Register - Security

Contagious Claude Code bug Anthropic ignored promptly spreads to Cowork

β€” January 15th 2026 at 19:15

Office workers without AI experience warned to watch for prompt injection attacks - good luck with that

Anthropic's tendency to wave off prompt-injection risks is rearing its head in the company's new Cowork productivity AI, which suffers from a Files API exfiltration attack chain first disclosed last October and acknowledged but not fixed by Anthropic.…

☐ β˜† βœ‡ The Register - Security

A simple CodeBuild flaw put every AWS environment at risk – and pwned 'the central nervous system of the cloud'

β€” January 15th 2026 at 15:00

And it's 'not unique to AWS,' researcher tells The Reg

A critical misconfiguration in AWS's CodeBuild service allowed complete takeover of the cloud provider's own GitHub repositories and put every AWS environment in the world at risk, according to Wiz security researchers.…

☐ β˜† βœ‡ The Register - Security

US regulator tells GM to hit the brakes on customer tracking

β€” January 15th 2026 at 13:30

Smart Driver pitched as safety app, but feds claim it's a data-harvesting scheme that jacked up premiums

The Federal Trade Commission has banned General Motors and subsidiary OnStar from sharing drivers' precise location and behavior data with consumer reporting agencies for five years under a 20-year consent order finalized January 14.…

☐ β˜† βœ‡ The Register - Security

Woman bailed as cops probe doctor's surgery data breach

β€” January 15th 2026 at 13:24

Suspect assisting West Midlands Police over alleged theft at Walsall GP practice

The UK's West Midlands Police has released a woman on bail as part of an investigation into a data breach at a Walsall general practitioner's (GP) surgery.…

☐ β˜† βœ‡ The Register - Security

Microsoft taps UK courts to dismantle cybercrime host RedVDS

β€” January 15th 2026 at 11:32

Redmond says cheap virtual desktops powered a global wave of phishing and fraud

Microsoft has taken its cybercrime fight to the UK in its first major civil action outside the US, moving to shut down RedVDS, a virtual desktop service used to power phishing and fraud at global scale.…

☐ β˜† βœ‡ The Register - Security

Ofcom keeps X under the microscope despite Grok 'nudify' fix

β€” January 15th 2026 at 11:18

Cold milk poured over 'spicy mode,' but it might not be enough to escape a huge fine

Ofcom is continuing with its investigation into X, despite the social media platform saying it will block Grok from digitally undressing people.…

☐ β˜† βœ‡ The Register - Security

AWS flips switch on Euro cloud as customers fret about digital sovereignty

β€” January 15th 2026 at 09:30

EU-only ops, German subsidiaries, and a pinky promise your data won't end up in Uncle Sam's hands

Amid continued trade and geopolitical volatility between Europe and the US, Amazon Web Services is making its European Sovereign Cloud generally available today and plans to expand so-called Local Zones.…

☐ β˜† βœ‡ The Register - Security

New Linux malware targets the cloud, steals creds, and then vanishes

β€” January 14th 2026 at 20:39

Cloud-native, 37 plugins … an attacker's dream

A brand-new Linux malware named VoidLink targets victims' cloud infrastructure with more than 30 plugins that allow attackers to perform a range of illicit activities, from silent reconnaissance and credential theft to lateral movement and container abuse. …

☐ β˜† βœ‡ The Register - Security

France fines telcos €42M for sub-par security prior to 24M customer breach

β€” January 14th 2026 at 15:17

Three major GDPR violations, including a lack of basic security controls, lead to hefty dent in profits

The French data protection regulator, CNIL, today issued a collective €42 million ($48.9 million) fine to two French telecom companies for GDPR violations stemming from a data breach.…

☐ β˜† βœ‡ The Register - Security

'Imagination the limit': DeadLock ransomware gang using smart contracts to hide their work

β€” January 14th 2026 at 14:16

New crooks on the block get crafty with blockchain to evade defenses

Researchers at Group-IB say the DeadLock ransomware operation is using blockchain-based anti-detection methods to evade defenders' attempts to analyze their tradecraft.…

☐ β˜† βœ‡ The Register - Security

Cyber-stricken Belgian hospitals refuse ambulances, transfer critical patients

β€” January 14th 2026 at 12:52

Attack enters second day with major disruption to healthcare provision

Two hospitals in Belgium have cancelled surgeries and transferred critical patients to other facilities after shutting down servers following a cyberattack.…

☐ β˜† βœ‡ The Register - Security

Eurail passengers taken for a ride as data breach spills passports, bank details

β€” January 14th 2026 at 12:43

Travel biz tells customers to change passwords beyond its own services

Eurail has confirmed customer information was stolen in a data breach, according to notification emails sent out this week.…

☐ β˜† βœ‡ The Register - Security

UK backtracks on digital ID requirement for right to work

β€” January 14th 2026 at 12:20

U-turn leaves questions on costs, funding, and benefits unanswered

The UK government has backed down from making digital ID mandatory for proof of a right to work in the country, adding to confusion over the scheme's cost and purpose.…

☐ β˜† βœ‡ The Register - Security

Spanish power giant sparks breach probe amid claims of massive data grab

β€” January 14th 2026 at 10:15

Endesa says payment info stolen after alleged crook boasted of 1 TB-plus haul

Spanish energy giant Endesa is warning customers about a data breach after a cybercrim claimed to have walked off with a vast cache of personal information allegedly tied to more than 20 million people.…

☐ β˜† βœ‡ The Register - Security

Anthropic finds $1.5 million to help Python Foundation improve security

β€” January 14th 2026 at 06:25

AI upstart also upscales its Labs to find the next frontier

The Python Software Foundation (PSF) has an extra $1.5 million heading its way, after AI upstart Anthropic entered into a partnership aimed at improving security in the Python ecosystem.…

☐ β˜† βœ‡ The Register - Security

Windows info-disclosure 0-day bug gets a fix as CISA sounds alarm

β€” January 14th 2026 at 00:36

First Patch Tuesday of 2026 goes big

Microsoft and Uncle Sam have warned that a Windows bug disclosed today is already under attack.…

☐ β˜† βœ‡ The Register - Security

Popular Python libraries used in Hugging Face models subject to poisoned metadata attack

β€” January 13th 2026 at 21:17

The open-source libraries were created by Salesforce, Nvidia, and Apple with a Swiss group

Vulnerabilities in popular AI and ML Python libraries used in Hugging Face models with tens of millions of downloads allow remote attackers to hide malicious code in metadata. The code then executes automatically when a file containing the poisoned metadata is loaded.…

☐ β˜† βœ‡ The Register - Security

AI and automation could erase 10.4 million US roles by 2030

β€” January 13th 2026 at 17:00

Forrester models slow, structural shift rather than sudden employment collapse

AI-pocalypse AI and automation could wipe out 6.1 percent of jobs in the US by 2030 – equating to 10.4 million fewer positions that are held by humans today.…

☐ β˜† βœ‡ The Register - Security

Dutch cops cuff alleged AVCheck malware kingpin in Amsterdam

β€” January 13th 2026 at 14:32

33-year-old was under surveillance for some time before returning home from the UAE

Dutch police believe they have arrested a man behind the AVCheck online platform - a service used by cybercrims that Operation Endgame shuttered in May.…

☐ β˜† βœ‡ The Register - Security

Federal agencies told to fix or ditch Gogs as exploited zero-day lands on CISA hit list

β€” January 13th 2026 at 13:04

Git server flaw that attackers have been abusing for months has now caught the attention of US cyber cops

CISA has ordered federal agencies to stop using Gogs or lock it down immediately after a high-severity vulnerability in the self-hosted Git service was added to its Known Exploited Vulnerabilities (KEV) catalog.…

☐ β˜† βœ‡ The Register - Security

Mandiant open sources tool to prevent leaky Salesforce misconfigs

β€” January 13th 2026 at 12:34

AuraInspector automates the most common abuses and generates fixes for customers

Mandiant has released an open source tool to help Salesforce admins detect misconfigurations that could expose sensitive data.…

☐ β˜† βœ‡ The Register - Security

Court tosses appeal by hacker who opened port to coke smugglers with malware

β€” January 13th 2026 at 12:10

Dutchman fails to convince judges his trial was unfair because cops read his encrypted chats

A Dutch appeals court has kept a seven-year prison sentence in place for a man who hacked port IT systems with malware-stuffed USB sticks to help cocaine smugglers move containers, brushing off claims that police shouldn't have been reading his encrypted chats.…

☐ β˜† βœ‡ The Register - Security

Britain goes shopping for a rapid-fire missile to help Ukraine hit back

β€” January 13th 2026 at 10:15

Project Nightfall aims to deliver a UK-built long-range strike capability at speed

The British government is asking defense firms to rapidly produce a new ground-launched ballistic missile to aid Ukraine's fight against Russia - hardware that might also be adopted by UK's armed forces in future.…

☐ β˜† βœ‡ The Register - Security

India demands crypto outfits geolocate customers, get a selfie to prove they’re real

β€” January 13th 2026 at 02:48

Government is fed up with bad actors using digi-cash to fund dodgy deeds

India’s government has updated the regulations it imposes on cryptocurrency services providers, as part of its efforts to combat fraud, money laundering, and terrorism.…

☐ β˜† βœ‡ The Register - Security

No fire sale for firewalls as memory shortages could push prices higher

β€” January 12th 2026 at 22:41

In SEC filings, Fortinet and Palo Alto show shrinking product margins taking hold.

PCs and datacenters aren't the only devices that need DRAM. The global memory shortage is roiling the cybersecurity market, with the cost of firewalls expected to balloon and hit both customers and vendors in the pocketbook in 2026, according to research analysts Wedbush.…

☐ β˜† βœ‡ The Register - Security

'Violence-as-a-service' suspect arrested in Iraq, extradition underway

β€” January 12th 2026 at 22:40

Gang members 'systematically exploited children and young people,' cops say

A 21-year-old Swedish man accused of being a key organizer of violence-as-a-service linked to the Foxtrot criminal network, which police say has recruited and exploited minors, has been arrested in Iraq.…

☐ β˜† βœ‡ The Register - Security

Businesses in 2026: Maybe we should finally look into that AI security stuff

β€” January 12th 2026 at 18:29

Survey finds security checks nearly doubled in a year as leaders wise up

The number of organizations that have implemented methods for identifying security risks in the AI tools they use has almost doubled in the space of a year.…

☐ β˜† βœ‡ The Register - Security

Block CISO: We red-teamed our own AI agent to run an infostealer on an employee laptop

β€” January 12th 2026 at 16:46

Agents must be 'safer and better than humans,' James Nettesheim tells The Reg

exclusive When it comes to security, AI agents are like self-driving cars, according to Block Chief Information Security Officer James Nettesheim.…

☐ β˜† βœ‡ The Register - Security

Infamous BreachForums forum breached, spilling data on 325K users

β€” January 12th 2026 at 13:07

Website built around buying and selling stolen data has lost control of its own

Updated BreachForums, the serially resurrected cybercrime marketplace, has tripped over itself after a data breach spilled details tied to about 324,000 user accounts.…

☐ β˜† βœ‡ The Register - Security

Ofcom officially investigating X as Grok's nudify button stays switched on

β€” January 12th 2026 at 12:19

Tech minister Liz Kendall says the government will back a robust regulatory response

Ofcom is investigating X over potential violations of the Online Safety Act, Britian's comms watchdog has confirmed.…

☐ β˜† βœ‡ The Register - Security

Tories vow to boot under-16s off social media and ban phones in schools

β€” January 12th 2026 at 10:25

Opposition leader Kemi Badenoch pitches age limits and classroom curbs as fixes for behavior and mental health

The Tories have pledged to kick under-16s off social media, betting that banning teens from TikTok and Instagram will fix what they see as a growing crisis in kids' mental health and classroom behavior.…

☐ β˜† βœ‡ The Register - Security

India’s government denies it plans to demand smartphone source code

β€” January 12th 2026 at 04:37

Says ongoing talks about security are about understanding best practice, not strong-arming vendors

India’s government has denied that it is working on rules that would require smartphone manufacturers to provide access to their source code.…

☐ β˜† βœ‡ The Register - Security

Malaysia and Indonesia block X over failure to curb deepfake smut

β€” January 12th 2026 at 01:29

PLUS: Cambodia arrests alleged scam camp boss; Baidu spins out chip biz; Panasonic’s noodle shop plan; And more!

Asia in Brief The governments of Malaysia and Indonesia have suspended access to social network X, on grounds that it allows users to produce sexual imagery without users’ consent.…

☐ β˜† βœ‡ The Register - Security

Meta admits to Instagram password reset mess, denies data leak

β€” January 11th 2026 at 23:43

PLUS: Veeam patches critical vuln; Crims bribing dark web insiders; UK school takedown; And more

infosec in brief Meta has fixed a flaw in its Instagram service that allowed third parties to generate password reset emails, but denied the problem led to theft of users’ personal information.…

☐ β˜† βœ‡ The Register - Security

UK government exempting itself from flagship cyber law inspires little confidence

β€” January 10th 2026 at 09:29

Ministers promise equivalent standards just without the legal obligation

ANALYSIS From May's cyberattack on the Legal Aid Agency to the Foreign Office breach months later, cyber incidents have become increasingly common in UK government.…

☐ β˜† βœ‡ The Register - Security

How hackers are fighting back against ICE surveillance tech

β€” January 9th 2026 at 21:03

Remember when government agents didn't wear masks?

While watching us now seems like the least of its sins, the US Immigration and Customs Enforcement (ICE) was once best known (and despised) for its multi-billion-dollar surveillance tech budget.…

☐ β˜† βœ‡ The Register - Security

Putinswap: France trades alleged ransomware crook for conflict researcher

β€” January 9th 2026 at 16:07

Basketball player accused of aiding cybercrime gang extradition blocked in exchange for Swiss NGO consultant

France has released an alleged ransomware crook wanted by the US in exchange for a conflict researcher imprisoned in Russia.…

☐ β˜† βœ‡ The Register - Security

QR codes a powerful new phishing weapon in hands of Pyongyang cyberspies

β€” January 9th 2026 at 15:44

State-backed attackers are using QR codes to slip past enterprise security and help themselves to cloud logins, the FBI says

North Korean government hackers are turning QR codes into credential-stealing weapons, the FBI has warned, as Pyongyang's spies find new ways to duck enterprise security and help themselves to cloud logins.…

☐ β˜† βœ‡ The Register - Security

China-linked cybercrims abused VMware ESXi zero-days a year before disclosure

β€” January 9th 2026 at 13:28

Huntress analysis suggests VM escape bugs were already weaponized in the wild

Chinese-linked cybercriminals were sitting on a working VMware ESXi hypervisor escape kit more than a year before the bugs it relied on were made public.…

☐ β˜† βœ‡ The Register - Security

Grok told to cover up as UK weighs action over AI 'undressing'

β€” January 9th 2026 at 10:21

Image generation paywalled on X after ministers and regulators start asking awkward questions

Grok has yanked its image-generation toy out of the hands of most X users after the UK government openly weighed a ban over the AI feature that "undressed" people on command.…

☐ β˜† βœ‡ The Register - Security

Help desk read irrelevant script, so techies found and fixed their own problem

β€” January 9th 2026 at 07:26

As you should, when being told the only remedy is deleting everything and starting again

On Call 2025 has ended and a new year is upon us, but The Register will continue opening Friday mornings with a fresh installment of On Call – the reader-contributed column that tells your tales of tech support.…

☐ β˜† βœ‡ The Register - Security

As agents run amok, CrowdStrike's $740M SGNL deal aims to help get a grip on identity security

β€” January 8th 2026 at 22:09

Authentication is basically solved. Authorization is another thing entirely...

CrowdStrike has signed a $740 million deal to buy identity security startup SGNL. The move underscores the growing threat of identity-based attacks as companies struggle to secure skyrocketing numbers of non-human identities, including AI agents.…

☐ β˜† βœ‡ The Register - Security

Patch Cisco ISE bug now before attackers abuse proof-of-concept exploit

β€” January 8th 2026 at 18:43

No reports of active exploitation … yet

Cisco patched a bug in its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) products that allows remote attackers with admin-level privileges to access sensitive information - and warned that a public, proof-of-concept exploit for the flaw exists online.…

☐ β˜† βœ‡ The Register - Security

Ransomware attacks kept climbing in 2025 as gangs refused to stay dead

β€” January 8th 2026 at 14:47

Cop wins hit crime infrastructure, not the people behind it

If 2025 was meant to be the year ransomware started dying, nobody appears to have told the attackers.…

☐ β˜† βœ‡ The Register - Security

CISA flags actively exploited Office relic alongside fresh HPE flaw

β€” January 8th 2026 at 13:44

Max-severity OneView hole joins a PowerPoint bug that should've been retired years ago

CISA has added a pair of security holes to its actively exploited list, warning that attackers are now abusing a maximum-severity bug in HPE's OneView management software and a years-old flaw in Microsoft Office.…

☐ β˜† βœ‡ The Register - Security

UK regulators swarm X after Grok generated nudes from photos

β€” January 8th 2026 at 12:40

Lawyers say Musk's platform may face punishment under Online Safety Act priority offenses

Elon Musk's X platform is under fire as UK regulators close in on mounting reports that the platform's AI chatbot, Grok, is generating sexual imagery without users' consent.…

☐ β˜† βœ‡ The Register - Security

Maximum-severity n8n flaw lets randos run your automation server

β€” January 8th 2026 at 11:40

Unauthenticated RCE means anyone on the network can seize full control

A maximum-severity bug in the popular automation platform n8n has left an estimated 100,000 servers wide open to complete takeover, courtesy of a flaw so bad it doesn't even require logging in.…

☐ β˜† βœ‡ The Register - Security

OpenAI putting bandaids on bandaids as prompt injection problems keep festering

β€” January 8th 2026 at 11:01

Happy Groundhog Day!

Security researchers at Radware say they've identified several vulnerabilities in OpenAI's ChatGPT service that allow the exfiltration of personal information.…

☐ β˜† βœ‡ The Register - Security

Yes, criminals are using AI to vibe-code malware

β€” January 8th 2026 at 11:00

They also hallucinate when writing ransomware code

Interview With everyone from would-be developers to six-year-old kids jumping on the vibe coding bandwagon, it shouldn't be surprising that criminals like automated coding tools too.…

☐ β˜† βœ‡ The Register - Security

Logitech macOS mouse mayhem traced to expired dev certificate

β€” January 8th 2026 at 09:30

Company says it dropped the ball, apologizes for wasting people's time

Logitech says an expired developer certificate is to blame after swaths of customers were left infuriated when their mice malfunctioned.…

☐ β˜† βœ‡ The Register - Security

Cloudflare pours cold water on β€˜BGP weirdness preceded US attack on Venezuela’ theory

β€” January 8th 2026 at 06:00

Suggests rotten routing, not evidence of a cyber-strike before kinetic action

Cloudflare has poured cold water on a theory that the USA’s incursion into Venezuela coincided with a cyberattack on telecoms infrastructure.…

☐ β˜† βœ‡ The Register - Security

IBM's AI agent Bob easily duped to run malware, researchers show

β€” January 7th 2026 at 22:04

Prompt injection lets risky commands slip past guardrails

IBM describes its coding agent thus: "Bob is your AI software development partner that understands your intent, repo, and security standards." Unfortunately, Bob doesn't always follow those security standards.…

❌