FreshRSS

πŸ”’
❌ Secure Planet Training Courses Updated For 2019 - Click Here
There are new available articles, click to refresh the page.
☐ β˜† βœ‡ The Register - Security

From pr0n to playlists and paperclips, trio of breaches spills data of millions

β€” December 16th 2025 at 12:33

Adult site, streaming platform, and Japanese retailer expose user info, but not credentials

Three very different companies have now confirmed data breaches affecting millions of users – each insisting the damage stopped well short of passwords and payment details.…

☐ β˜† βœ‡ The Register - Security

MI6 chief: We'll be as fluent in Python as we are in Russian

β€” December 16th 2025 at 11:45

New spy boss says officers must master code alongside tradecraft as agency navigates 'space between peace and war'

New MI6 chief Blaise Metreweli outlined her vision for technology-augmented intelligence gathering in her first public speech on December 15, warning that the UK operates "in a space between peace and war."…

☐ β˜† βœ‡ The Register - Security

PwC on using AI to turn cybersecurity risk into competitive advantage

β€” December 16th 2025 at 05:50

PwC supports clients across the full cyber lifecycle

Sponsored Post Managing cybersecurity risk has never been simple, but in today's threat landscape it can also become a source of strength. PwC believes that AI is now central to that transformation, helping organizations not just react faster to attacks, but evolve their defences with greater confidence.…

☐ β˜† βœ‡ The Register - Security

No, SoundCloud hasn’t started tuning out VPNs. It’s mopping up after a cyberattack

β€” December 16th 2025 at 05:20

Bum note for 20 percent of users whose data leaked

Music hosting and streaming service SoundCloud has admitted it suffered a cyberattack.…

☐ β˜† βœ‡ The Register - Security

Amazon security boss blames Russia's GRU for years-long energy-sector hacks

β€” December 15th 2025 at 23:34

'Sustained focus on Western critical infrastructure'

Russia's Main Intelligence Directorate (GRU) is behind a years-long campaign targeting energy, telecommunications, and tech providers, stealing credentials and compromising misconfigured devices hosted on AWS to give the Kremlin's snoops persistent access to sensitive networks, according to Amazon's security boss.…

☐ β˜† βœ‡ The Register - Security

China, Iran are having a field day with React2Shell, Google warns

β€” December 15th 2025 at 17:53

Who hasn't exploited this max-severity flaw?

At least five more Chinese spy crews, Iran-linked goons, and financially motivated criminals are now attacking React2Shell, a maximum-severity flaw in the widely used React JavaScript library, according to Google.…

☐ β˜† βœ‡ The Register - Security

Delay to European Central Bank messaging project cost the Bank of England Β£23M

β€” December 15th 2025 at 12:50

Watchdog links schedule change to replanning of UK payments system overhaul

The European Central Bank's (ECB) decision to delay its move to a new messaging standard in 2022 ended up costing the Bank of England Β£23 million as it was forced to adjust migration to a new settlement system to avoid compounding risks.…

☐ β˜† βœ‡ The Register - Security

JLR: Payroll data stolen in cybercrime that shook UK economy

β€” December 15th 2025 at 12:08

Automaker admits raid that crippled its factories in August led to the theft of sensitive info

Jaguar Land Rover (JLR) has reportedly told staff the cyber raid that crippled its operations in August didn't just bring production to a screeching halt – it also walked off with the personal payroll data of thousands of employees.…

☐ β˜† βœ‡ The Register - Security

Apple, Google forced to issue emergency 0-day patches

β€” December 15th 2025 at 11:01

Both admit attackers were already exploiting the bugs, with scant detail and hints of spyware-grade abuse

Apple and Google have both issued emergency patches after zero-day bugs were caught being actively exploited in what the companies describe as "sophisticated" real-world attacks.…

☐ β˜† βœ‡ The Register - Security

Denmark takes a Viking swing at VPN-enabled piracy

β€” December 15th 2025 at 10:40

Minister insists 'modest' bill is not an assault on privacy-preserving tech

The Danish government wants the public to weigh in on its proposed laws restricting use of VPNs to access certain corners of the internet.…

☐ β˜† βœ‡ The Register - Security

Legal protection for ethical hacking under Computer Misuse Act is only the first step

β€” December 15th 2025 at 09:30

I'm dreaming of a white hat mass

Opinion It was 40 years ago that four young British hackers set about changing the law, although they didn't know it at the time. It was a cross-platform attack including a ZX Spectrum, a BBC Micro, and a Tatung Einstein slamming British Telecom's Prestel service over dial-up modems at 75 bits per second.…

☐ β˜† βœ‡ The Register - Security

Starlink claims Chinese launch came within 200 meters of broadband satellite

β€” December 15th 2025 at 02:02

PLUS: Drugs found in ink cartridges; Censorship fighters criticize Vultr; Coupang CEO resigns; And more!

Asia In Brief A SpaceX executive has claimed that a Chinese satellite launch came within 200 meters of hitting a Starlink satellite.…

☐ β˜† βœ‡ The Register - Security

Honeypots can help defenders, or damn them if implemented badly

β€” December 14th 2025 at 23:26

PLUS: Crims could burn your AI budgets thanks to weak defaults; CISA's top 25 vulns for 2025; And more

Infosec In Brief The UK's National Cyber Security Centre (NCSC) has found that cyber-deception tactics such as honeypots and decoy accounts designed to fool attackers can be useful if implemented very carefully.…

☐ β˜† βœ‡ The Register - Security

Microsoft RasMan DoS 0-day gets unofficial patch - and a working exploit

β€” December 12th 2025 at 22:29

Exploit hasn't been picked up by any malware detection engines, CEO tells The Reg

A Microsoft zero-day vulnerability that allows an unprivileged user to crash the Windows Remote Access Connection Manager (RasMan) service now has a free, unofficial patch - with no word as to when Redmond plans to release an official one - along with a working exploit circulating online.…

☐ β˜† βœ‡ The Register - Security

New React vulns leak secrets, invite DoS attacks

β€” December 12th 2025 at 18:23

And the earlier React2Shell patch is vulnerable

If you're running React Server Components, you just can't catch a break. In addition to already-reported flaws, newly discovered bugs allow attackers to hang vulnerable servers and potentially leak Server Function source code, so anyone using RSC or frameworks that support it should patch quickly.…

☐ β˜† βœ‡ The Register - Security

Microsoft promises more bug payouts, with or without a bounty program

β€” December 12th 2025 at 13:35

Critical vulnerabilities found in third-party applications eligible for award under 'in scope by default' move

Microsoft is overhauling its bug bounty program to reward exploit hunters for finding vulnerabilities across all its products and services, even those without established bounty schemes.…

☐ β˜† βœ‡ The Register - Security

Uncle Sam sues ex-Accenture manager over Army cloud security claims

β€” December 12th 2025 at 13:25

Justice Department alleges federal auditors were misled over compliance with FedRAMP and DoD requirements

The US is suing a former senior manager at Accenture for allegedly misleading the government about the security of an Army cloud platform.…

☐ β˜† βœ‡ The Register - Security

UK watchdog urged to probe GDPR failures in Home Office eVisa rollout

β€” December 12th 2025 at 12:36

Rights groups say digital-only record is leaking data and courting trouble

Civil society groups are urging the UK's data watchdog to investigate whether the Home Office's digital-only eVisa scheme is breaching GDPR, sounding the alarm about systemic data errors and design failures that are exposing sensitive personal information while leaving migrants unable to prove their lawful status.…

☐ β˜† βœ‡ The Register - Security

Half of exposed React servers remain unpatched amid active exploitation

β€” December 12th 2025 at 11:31

Wiz says React2Shell attacks accelerating, ranging from cryptominers to state-linked crews

Half of the internet-facing systems vulnerable to a fast-moving React remote code execution flaw remain unpatched, even as exploitation has exploded into more than a dozen active attack clusters ranging from bargain-basement cryptominers to state-linked intrusion tooling.…

☐ β˜† βœ‡ The Register - Security

Crypto-crasher Do Kwon jailed for 15 years over $40bn UST bust

β€” December 12th 2025 at 01:53

Judge said his fraud was on 'epic, generational scale'

Terraform Labs founder Do Kwon will spend 15 years in jail after pleading guilty to committing fraud.…

☐ β˜† βœ‡ The Register - Security

Russian hackers debut simple ransomware service, but store keys in plain text

β€” December 11th 2025 at 20:56

Operators accidentally left a way for you to get your data back

CyberVolk, a pro-Russian hacktivist crew, is back after months of silence with a new ransomware service. There's some bad news and some good news here.…

☐ β˜† βœ‡ The Register - Security

Google fixes super-secret 8th Chrome 0-day

β€” December 11th 2025 at 17:09

No details, no CVE, update your browser now

Google issued an emergency fix for a Chrome vulnerability already under exploitation, which marks the world's most popular browser's eighth zero-day bug of 2025.…

☐ β˜† βœ‡ The Register - Security

LastPass hammered with Β£1.2M fine for 2022 breach fiasco

β€” December 11th 2025 at 16:45

UK data regulator says failures were unacceptable for a company managing the world's passwords

The UK's Information Commissioner's Office (ICO) says LastPass must cough up Β£1.2 million ($1.6 million) after its two-part 2022 data breach compromised information from up to 1.6 million UK users.…

☐ β˜† βœ‡ The Register - Security

Researcher claims Salt Typhoon spies attended Cisco training scheme

β€” December 11th 2025 at 12:42

Skills gained later fed Beijing's cyber operations, according to SentinelLabs expert

A security researcher specializing in tracking China threats claims two of Salt Typhoon's members were former attendees of a training scheme run by Cisco.…

☐ β˜† βœ‡ The Register - Security

10K Docker images spray live cloud creds across the internet

β€” December 11th 2025 at 11:26

Flare warns devs are unwittingly publishing production-level secrets

Docker Hub has quietly become a treasure trove of live cloud keys and credentials, with more than 10,000 public container images exposing sensitive secrets from over 100 companies, including a Fortune 500 firm and a major bank.…

☐ β˜† βœ‡ The Register - Security

Users report chaos as Legal Aid Agency stumbles back online after cyberattack

β€” December 11th 2025 at 09:30

Workers frustrated with security-first changes to workflows and teething issues

Exclusive Seven months after a landmark cyberattack, the UK's Legal Aid Agency (LAA) says it's returning to pre-breach operations, although law firms are still wrestling with buggy and more laborious systems.…

☐ β˜† βœ‡ The Register - Security

700+ self-hosted Gits battered in 0-day attacks with no fix imminent

β€” December 10th 2025 at 21:31

More than half of internet-exposed instances already compromised

Attackers are actively exploiting a zero-day bug in Gogs, a popular self-hosted Git service, and the open source project doesn't yet have a fix.…

☐ β˜† βœ‡ The Register - Security

US extradites Ukrainian woman accused of hacking meat processing plant for Russia

β€” December 10th 2025 at 17:56

The digital intrusion allegedly caused thousands of pounds of meat to spoil and triggered an ammonia leak in the facility

A Ukrainian woman accused of hacking US public drinking water systems and a meat processing facility on behalf of Kremlin-backed cyber groups was extradited to the US earlier this year and will stand trial in early 2026.…

☐ β˜† βœ‡ The Register - Security

Microsoft won't fix .NET RCE bug affecting slew of enterprise apps, researchers say

β€” December 10th 2025 at 17:30

Devs and users should know better, Microsoft tells watchTowr

Updated Security researchers have revealed a .NET security flaw thought to affect a host of enterprise-grade products that they say Microsoft refuses to fix.…

☐ β˜† βœ‡ The Register - Security

Protecting value at risk - the role of a risk operations center

β€” December 10th 2025 at 16:00

Why should Keith Richards’ fingers inform your approach to risk?

Partner Content For years, celebrities have insured their body parts for vast sums of money. Mariah Carey allegedly insured her voice and legs for $70 million during a tour, according to TMZ; and Lloyd’s of LondonΒ was reported to have insured a wide range of celebrity body parts, from restauranteur Egon Ronay’s taste budsΒ to the fingers of Rolling Stones’ guitarist Keith Richards, which were insured for $1.6 million. …

☐ β˜† βœ‡ The Register - Security

Crisis in Icebergen: How NATO crafts stories to sharpen cyber skills

β€” December 10th 2025 at 12:29

1,500 military digital defenders spent the past week cleaning up a series of cyberattacks on fictional island

feature Andravia and Harbadus – two nations so often at odds with one another – were once again embroiled in conflict over the past seven days, which thoroughly tested NATO's cybersecurity experts' ability to coordinate defenses across battlefield domains.…

☐ β˜† βœ‡ The Register - Security

Microsoft reports 7.8-rated zero day, plus 56 more in December Patch Tuesday

β€” December 9th 2025 at 23:42

Plus critical critical Notepad++, Ivanti, and Fortinet updates, and one of these patches an under-attack security hole

Updated Happy December Patch Tuesday to all who celebrate. This month's patch party includes one Microsoft flaw under exploitation, plus two others listed as publicly known – but just 57 CVEs in total from Redmond.…

☐ β˜† βœ‡ The Register - Security

How to answer the door when the AI agents come knocking

β€” December 9th 2025 at 21:46

Identity management vendors like Okta see an opening to calm CISOs worried about agents running amok

The fear of AI agents running amok has thus far halted the wide deployment of these digital workhorses, Okta's president of Auth0, Shiv Ramji, told The Register.…

☐ β˜† βœ‡ The Register - Security

Porsche panic in Russia as pricey status symbols forget how to car

β€” December 9th 2025 at 17:16

Satellite silence trips immobilizers, leaving owners stuck

Hundreds of Porsches in Russia were rendered immobile last week, raising speculation of a hack, but the German carmaker tells The Register that its vehicles are secure.…

☐ β˜† βœ‡ The Register - Security

As humanoid robots enter the mainstream, security pros flag the risk of botnets on legs

β€” December 9th 2025 at 15:00

Have we learned nothing from sci-fi films and TV shows?

Interview Imagine botnets in physical form and you've got a pretty good idea of what could go wrong with the influx of AI-infused humanoid robots expected to integrate into society over the next few decades.…

☐ β˜† βœ‡ The Register - Security

UK to Europe: The time to counter Russia's information war machine is now

β€” December 9th 2025 at 12:49

Foreign secretary set to address senior diplomats later today

The UK's foreign secretary is calling for closer collaboration with Europe to combat the growing threat of information warfare as hybrid attacks target countries on the continent.…

☐ β˜† βœ‡ The Register - Security

UK finally vows to look at 35-year-old Computer Misuse Act

β€” December 9th 2025 at 10:15

As Portugal gives researchers a pass under cybersecurity law

Portugal has become the latest country to carve out protections for researchers under its cybersecurity law.…

☐ β˜† βœ‡ The Register - Security

Whitehall rejects Β£1.8B digital ID price tag – but won't say what it will cost

β€” December 9th 2025 at 09:30

Officials insist OBR relied on 'early estimate' and real figure won't emerge until next year

The head of the department delivering the UK government's digital identity scheme has rejected the Β£1.8 billion cost forecast by the Office for Budget Responsibility (OBR), but is not willing to provide an alternative until after a delayed consultation on the plans.…

☐ β˜† βœ‡ The Register - Security

Researchers spot 700 percent increase in hypervisor ransomware attacks

β€” December 9th 2025 at 06:41

Get your Hyper-V and VMware ESXi setups in order, people

Researchers at security software vendor Huntress say they’ve noticed a huge increase in ransomware attacks on hypervisors and urged users to ensure they’re as secure as can be and properly backed up.…

☐ β˜† βœ‡ The Register - Security

193 cybercrims arrested, accused of plotting 'violence-as-a-service'

β€” December 8th 2025 at 18:45

Minors groomed to kill and intimidate victims

Nearly 200 people, including minors accused of involvement in murder plots, have been arrested over the last six months as part of Europol's Operational Taskforce (OTF) GRIMM. The operation targets what cops call "violence-as-a-service" - crime crews recruiting kids and teens online to carry out contract killings and other real-world attacks.…

☐ β˜† βœ‡ The Register - Security

UK moves to strengthen undersea cable defenses as Russian snooping ramps up

β€” December 8th 2025 at 14:00

Atlantic Bastion combines AI systems with warships to counter increased surveillance

The UK government has announced enhanced protection for undersea cables using autonomous vessels alongside crewed warships and aircraft, responding to escalating Russian surveillance activities.…

☐ β˜† βœ‡ The Register - Security

Home Office kept police facial recognition flaws to itself, UK data watchdog fumes

β€” December 8th 2025 at 12:16

Regulator disappointed as soon-to-be-scrapped algo's problems remained a secret despite consistent engagement

The UK's data protection watchdog has criticized the Home Office for failing to disclose significant biases in police facial recognition technology, despite regular engagement between the organizations.…

☐ β˜† βœ‡ The Register - Security

Barts Health seeks High Court block after Clop pillages NHS trust data

β€” December 8th 2025 at 11:12

Body confirms patient and staff details siphoned via Oracle EBS flaw as gang threatens to leak haul

Barts Health NHS Trust has confirmed that patient and staff data was stolen in Clop's mass-exploitation of Oracle's E-Business Suite (EBS), and says it is now taking legal action in an effort to stop the gang publishing any of the snatched information.…

☐ β˜† βœ‡ The Register - Security

Block all AI browsers for the foreseeable future: Gartner

β€” December 8th 2025 at 04:57

Analysts worry lazy users could have agents complete mandatory infosec training, and attackers could do far nastier things

Agentic browsers are too risky for most organizations to use, according to analyst firm Gartner.…

☐ β˜† βœ‡ The Register - Security

China’s first reusable rocket explodes, but its onboard Ethernet network flew

β€” December 8th 2025 at 01:56

PLUS: South Korea to strengthen security standards; Canon closes Chinese printer plant; APAC datacenter capacity to triple by 2029; And more

Asia In Brief Chinese rocketry outfit LandSpace last week flew what it hoped would be the country’s first reusable rocket, only to watch it explode while attempting to land.…

☐ β˜† βœ‡ The Register - Security

Apache warns of 10.0-rated flaw in Tika metadata ingestion tool

β€” December 8th 2025 at 00:10

PLUS: New kind of DDOS from the Americas; Predator still hunting spyware targets; NIST issues IoT advice; And more!

Infosec in Brief The Apache Foundation last week warned of a 10.0-rated flaw in its Tika toolkit.…

☐ β˜† βœ‡ The Register - Security

Death to one-time text codes: Passkeys are the new hotness in MFA

β€” December 6th 2025 at 09:11

Wanna know a secret?

Whether you're logging into your bank, health insurance, or even your email, most services today do not live by passwords alone. Now commonplace, multifactor authentication (MFA) requires users to enter a second or third proof of identity. However, not all forms of MFA are created equal, and the one-time passwords orgs send to your phone have holes so big you could drive a truck through them.…

☐ β˜† βœ‡ The Register - Security

Crims using social media images, videos in 'virtual kidnapping' scams

β€” December 5th 2025 at 23:23

Proof of life? Or an active social media presence?

Criminals are altering social media and other publicly available images of people to use as fake proof of life photos in "virtual kidnapping" and extortion scams, the FBI warned on Friday. …

☐ β˜† βœ‡ The Register - Security

Novel clickjacking attack relies on CSS and SVG

β€” December 5th 2025 at 21:55

Who needs JavaScript?

Security researcher Lyra Rebane has devised a novel clickjacking attack that relies on Scalable Vector Graphics (SVG) and Cascading Style Sheets (CSS).…

☐ β˜† βœ‡ The Register - Security

Cloudflare blames Friday outage on borked fix for React2shell vuln

β€” December 5th 2025 at 21:46

Security community needs to rally and share more info faster, one researcher says

Amid new reports of attackers pummeling a maximum security hole (CVE-2025-55182) in the React JavaScript library, Cloudflare's technology chief said his company took down its own network, forcing a widespread outage early Friday, to patch React2Shell.…

☐ β˜† βœ‡ The Register - Security

Asus supplier hit by ransomware attack as gang flaunts alleged 1 TB haul

β€” December 5th 2025 at 14:51

Laptop maker says a vendor breach exposed some phone camera code, but not its own systems

Asus has admitted that a third-party supplier was popped by cybercrims after the Everest ransomware gang claimed it had rifled through the tech titan's internal files.…

☐ β˜† βœ‡ The Register - Security

Beijing-linked hackers are hammering max-severity React bug, AWS warns

β€” December 5th 2025 at 14:10

State-backed attackers started poking flaw as soon as it dropped – anyone still unpatched is on borrowed time

Amazon has warned that China-nexus hacking crews began hammering the critical React "React2Shell" vulnerability within hours of disclosure, turning a theoretical CVSS-10 hole into a live-fire incident almost immediately.…

☐ β˜† βœ‡ The Register - Security

UK pushes ahead with facial recognition expansion despite civil liberties backlash

β€” December 5th 2025 at 11:14

Plan would create statutory powers for police use of biometrics, prompting warnings of mass surveillance

The UK government has kicked off plans to ramp up police use of facial recognition, undeterred by a mounting civil liberties backlash and fresh warnings that any expansion risks turning public spaces into biometric dragnets.…

☐ β˜† βœ‡ The Register - Security

Bots, bias, and bunk: How can you tell what's real on the net?

β€” December 5th 2025 at 09:30

You can improve the odds by combining skepticism, verification habits, and a few technical checks

Opinion Liars, cranks, and con artists have always been with us. It's just that nowadays their reach has gone from the local pub to the globe.…

☐ β˜† βœ‡ The Register - Security

An AI for an AI: Anthropic says AI agents require AI defense

β€” December 5th 2025 at 00:30

Automated software keeps getting better at pilfering cryptocurrency

Anthropic could have scored an easy $4.6 million by using its Claude AI models to find and exploit vulnerabilities in blockchain smart contracts.…

☐ β˜† βœ‡ The Register - Security

PRC spies Brickstormed their way into critical US networks and remained hidden for years

β€” December 4th 2025 at 22:10

'Dozens' of US orgs infected

Chinese cyberspies maintained long-term access to critical networks – sometimes for years – and used this access to infect computers with malware and steal data, according to Thursday warnings from government agencies and private security firms.…

☐ β˜† βœ‡ The Register - Security

Hegseth needs to go to secure messaging school, report says

β€” December 4th 2025 at 21:09

He's not alone: DoD inspector general says the whole Defense Department has a messaging security problem

US Defense Secretary Pete Hegseth definitely broke the rules when he sent sensitive information to a Signal chat group, say Pentagon auditors, but he's not the only one using insecure messaging, and everyone needs better training.…

☐ β˜† βœ‡ The Register - Security

Twins who hacked State Dept hired to work for gov again, now charged with deleting databases

β€” December 4th 2025 at 19:48

And then they asked an AI to help cover their tracks

Vetting staff who handle sensitive government systems is wise, and so is cutting off their access the moment they're fired. Prosecutors say a federal contractor learned this the hard way when twin brothers previously convicted of hacking-related offenses allegedly used lingering access to delete nearly 100 government databases, including systems tied to Homeland Security and other agencies, within minutes of being terminated.…

☐ β˜† βœ‡ The Register - Security

Microsoft quietly shuts down Windows shortcut flaw after years of espionage abuse

β€” December 4th 2025 at 15:01

Silent Patch Tuesday mitigation ends ability to hide malicious commands in .lnk files

Microsoft has quietly closed off a critical Windows shortcut file bug long abused by espionage and cybercrime networks.…

☐ β˜† βœ‡ The Register - Security

Aisuru botnet turns Q3 into a terabit-scale stress test for the entire internet

β€” December 4th 2025 at 13:07

Cloudflare data shows 29.7 Tbps record-breaker landed amid 87% surge in network-layer attacks

The internet has spent the past three months ducking for cover as the Aisuru botnet hurled record-shattering DDoS barrages from an army of up to 4 million infected machines.…

❌