FreshRSS

πŸ”’
❌ Secure Planet Training Courses Updated For 2019 - Click Here
There are new available articles, click to refresh the page.
☐ β˜† βœ‡ The Register - Security

Devs are writing VS Code extensions that blab secrets by the bucketload

β€” October 15th 2025 at 15:35

Vibe coding may have played a role in what took researchers months to fix

Developers of VS Code extensions are leaking sensitive secrets left, right and center, according to researchers who worked with Microsoft to combat an issue that could have led to some nasty supply chain attacks.…

☐ β˜† βœ‡ The Register - Security

Capita fined Β£14M after 58-hour delay exposed 6.6M records

β€” October 15th 2025 at 11:01

ICO makes example of outsourcing giant over sluggish cyber response

The UK's Information Commissioner's Office (ICO) has issued a Β£14 million ($18.6 million) penalty to outsourcing giant Capita following a catastrophic 2023 cyberattack that exposed the personal data of 6.6 million people.…

☐ β˜† βœ‡ The Register - Security

Asahi breach leaves bitter taste as brewer fears personal data slurped

β€” October 14th 2025 at 14:12

Japan's beer behemoth still mopping up after ransomware spill that disrupted deliveries and delayed results

Asahi's cyber hangover just got worse, with the brewer now admitting that personal information may have been tapped in last month's attack.…

☐ β˜† βœ‡ The Register - Security

Mozilla is recruiting beta testers for a free, baked-in Firefox VPN

β€” October 14th 2025 at 13:28

Lucky few randomly selected to trial the feature, which won't fully roll out for several months

Mozilla is working on a built-in VPN for Firefox, with beta tests opening to select users shortly.…

☐ β˜† βœ‡ The Register - Security

Oracle rushes out another emergency E-Business Suite patch as Clop fallout widens

β€” October 14th 2025 at 12:32

Latest in a long line of EBS flaws leta miscreants remotely compromise enterprise systems to pinch sensitive data

Oracle is rushing out another emergency patch for its embattled E-Business Suite as the fallout from the Clop-linked attacks continues to spread.…

☐ β˜† βœ‡ The Register - Security

British govt agents demand action after UK mega-cyberattacks surge 50%

β€” October 14th 2025 at 10:51

Warn businesses to act now as high-severity incidents keep climbing

Cyberattacks that meet upper severity thresholds set by the UK government's cyber agents have risen 50 percent in the last year, despite almost zero change in the volume of cases handled.…

☐ β˜† βœ‡ The Register - Security

EU biometric border system launch hits inevitable teething problems

β€” October 14th 2025 at 06:45

Malfunctioning equipment and manual processing cause 90-minute waits

The European Union's new biometric Exit/Entry System (EES) got off to a chaotic start at Prague's international airport, with travelers facing lengthy queues and malfunctioning equipment forcing border staff to process arrivals manually.…

☐ β˜† βœ‡ The Register - Security

Scattered Lapsus$ Hunters rage-quit the internet (again), promise to return next year

β€” October 13th 2025 at 16:17

'We will never stop,' say crooks, despite retiring twice in the space of a month

The Scattered Lapsus$ Hunters (SLSH) cybercrime collective - compriseed primarily of teenagers and twenty-somethings - announced it will go dark until 2026 following the FBI's seizure of its clearweb site.…

☐ β˜† βœ‡ The Register - Security

Microsoft 'illegally' tracked students via 365 Education, says data watchdog

β€” October 13th 2025 at 13:38

Redmond argued schools, education authorities are responsible for GDPR

An Austrian digital privacy group has claimed victory over Microsoft after the country's data protection regulator ruled the software giant "illegally" tracked students via its 365 Education platform and used their data.…

☐ β˜† βœ‡ The Register - Security

China probes Qualcomm's Autotalks deal amid rising US trade tensions

β€” October 13th 2025 at 12:21

Beijing insists it's business as usual – Washington might see it differently

China's competition regulator has launched an investigation into Qualcomm's purchase of Israeli firm Autotalks, the latest salvo in the escalating tech trade war between Washington and Beijing.…

☐ β˜† βœ‡ The Register - Security

Ofcom fines 4chan Β£20K and counting for pretending UK's Online Safety Act doesn't exist

β€” October 13th 2025 at 11:10

Regulator warns penalties will pile up until internet toilet does its paperwork

Ofcom, the UK's Online Safety Act regulator, has fined online message board 4chan Β£20,000 ($26,680) for failing to protect children from harmful content.…

☐ β˜† βœ‡ The Register - Security

Dutch government puts Nexperia on a short leash over chip security fears

β€” October 13th 2025 at 11:01

Minister invokes powers to stop firm shifting knowledge to China, citing governance shortcomings

The Dutch government has placed Nexperia - a Chinese-owned semiconductor company that previously operated Britain's Newport Wafer Fab β€” under special administrative measures, citing serious governance failures that threaten European tech security.…

☐ β˜† βœ‡ The Register - Security

Pro-Russia hacktivist group dies of cringe after falling into researchers' trap

β€” October 10th 2025 at 14:16

Forescout's phony water plant fooled TwoNet into claiming a fake cyber victory – then it quietly shut up shop

Security researchers say they duped pro-Russia cybercriminals into targeting a fake critical infrastructure organization, which the crew later claimed - via their Telegram group - to be a real-world attack.…

☐ β˜† βœ‡ The Register - Security

Microsoft warns of 'payroll pirate' crew looting US university salaries

β€” October 10th 2025 at 13:21

Crooks phish campus staff, slip into HR systems, and quietly reroute paychecks

Microsoft's Threat Intelligence team has sounded the alarm over a new financially-motivated cybercrime spree that is raiding US university payroll systems.…

☐ β˜† βœ‡ The Register - Security

Cops nuke BreachForums (again) amid cybercrime supergroup extortion blitz

β€” October 10th 2025 at 10:19

US and French fuzz pull the plug on Scattered Lapsus$ Hunters' latest leak shop targeting Salesforce

US authorities have seized the latest incarnation of BreachForums, the cybercriminal bazaar recently reborn under the stewardship of the so-called Scattered Lapsus$ Hunters, with help from French cyber cops and the Paris prosecutor's office.…

☐ β˜† βœ‡ The Register - Security

UK techies' union warns members after breach exposes sensitive personal details

β€” October 10th 2025 at 09:41

Prospect apologizes for cyber gaffe affecting up to 160K members

UK trade union Prospect is notifying members of a breach that involved data such as sexual orientation and disabilities.…

☐ β˜† βœ‡ The Register - Security

It's trivially easy to poison LLMs into spitting out gibberish, says Anthropic

β€” October 9th 2025 at 20:45

Just 250 malicious training documents can poison a 13B parameter model - that's 0.00016% of a whole dataset

Poisoning AI models might be way easier than previously thought if an Anthropic study is anything to go on. …

☐ β˜† βœ‡ The Register - Security

SonicWall breach hits every cloud backup customer after 5% claim goes up in smoke

β€” October 9th 2025 at 13:30

Affects users regardless of when their backups were created

SonicWall has admitted that all customers who used its cloud backup service to store firewall configuration files were affected by a cybersecurity incident first disclosed in mid-September, walking back earlier assurances that only a small fraction of users were impacted.…

☐ β˜† βœ‡ The Register - Security

Take this rob and shove it! Salesforce issues stern retort to ransomware extort

β€” October 8th 2025 at 17:20

CRM giant 'will not engage, negotiate with, or pay' the scumbags

Salesforce won't pay a ransom demand to criminals who claim to have stolen nearly 1 billion customer records and are threatening to leak the data if the CRM giant doesn't pony up some cash.…

☐ β˜† βœ‡ The Register - Security

Germany slams brakes on EU's Chat Control device-scanning snoopfest

β€” October 8th 2025 at 12:53

Berlin's opposition likely kills off Brussels' bid to scan everyone's messages

Germany has committed to oppose the EU's controversial "Chat Control" regulations following huge pressure from multiple activists and major organizations.…

☐ β˜† βœ‡ The Register - Security

Employees regularly paste company secrets into ChatGPT

β€” October 7th 2025 at 20:18

Microsoft Copilot, not so much

Employees could be opening up to OpenAI in ways that put sensitive data at risk. According to a study by security biz LayerX, a large number of corporate users paste Personally Identifiable Information (PII) or Payment Card Industry (PCI) numbers right into ChatGPT, even if they're using the bot without permission.…

☐ β˜† βœ‡ The Register - Security

Nearly a year after attack, US medical scanning biz gets clear image of stolen patient data

β€” October 7th 2025 at 16:15

No fraud monitoring and no apology after miscreants make off with medical, financial data

Florida-based Doctors Imaging Group has admitted that the sensitive medical and financial data of 171,862 patients was stolen during the course of a November 2024 cyberattack.…

☐ β˜† βœ‡ The Register - Security

Police and military radio maker BK Technologies cops to cyber break-in

β€” October 7th 2025 at 15:55

Florida comms outfit serving cops, firefighters, and the military says hackers pinched some employee data but insists its systems stayed online

BK Technologies, the Florida-based maker of mission-critical radios for US police, fire, and defense customers, has confessed to a cyber intrusion that briefly rattled its IT systems last month.…

☐ β˜† βœ‡ The Register - Security

OpenAI bans suspected Chinese accounts using ChatGPT to plan surveillance

β€” October 7th 2025 at 15:36

It also banned some suspected Russian accounts trying to create influence campaigns and malware

OpenAI has banned ChatGPT accounts believed to be linked to Chinese government entities attempting to use AI models to surveil individuals and social media accounts.…

☐ β˜† βœ‡ The Register - Security

Britain eyes satellite laser warning system and carrier-launched jet drones

β€” October 7th 2025 at 09:13

Space sensors and UAVs at sea top MoD's list in new wave of cutting-edge projects

The UK is pressing ahead with cutting-edge defense projects, the latest including research to protect satellites from laser attack and a technology demonstrator for a jet-powered drone to operate from Royal Navy carriers.…

☐ β˜† βœ‡ The Register - Security

UK Home Office opens wallet for Β£60M automated number plate project

β€” October 7th 2025 at 08:30

Department eyes new app to tap national ANPR data for live alerts, searches, and integrations

The UK's Home Office is inviting tech suppliers to take part in a Β£60 million "market engagement" for an application that uses data from automated number plate recognition (ANPR) systems.…

☐ β˜† βœ‡ The Register - Security

Credential stuffing: Β£2.31 million fine shows passwords are still the weakest link

β€” October 7th 2025 at 08:00

How recycled passwords and poor security habits are fueling a cybercrime gold rush

Partner Content If you're still using "password123" for more than one account, there's a good chance you've already exposed yourself to credential stuffing attacks β€” one of the most prevalent and damaging forms of automated cybercrime today. Just ask the 6.9 million users of 23andMe who discovered their personal details were compromised when cybercriminals used recycled credentials from other breaches to infiltrate their accounts.…

☐ β˜† βœ‡ The Register - Security

Scattered Lapsus$ Hunters offering $10 in Bitcoin to 'endlessly harass' execs

β€” October 6th 2025 at 15:41

Crime group claims to have already doled out $1K to those in it 'for money and for the love of the game'

Scattered Lapsus$ Hunters has launched an unusual crowdsourced extortion scheme, offering $10 in Bitcoin to anyone willing to help pressure their alleged victims into paying ransoms.…

☐ β˜† βœ‡ The Register - Security

Radiant Group won't touch kids' data now, but apparently hospitals are fair game

β€” October 6th 2025 at 13:20

Ransomware crooks utterly fail to find moral compass

First they targeted a preschool network, now new kids on the ransomware block Radiant Group say they've hit a hospital in the US, continuing their deplorable early cybercrime careers.…

☐ β˜† βœ‡ The Register - Security

Thieves steal IDs and payment info after data leaks from Discord support vendor

β€” October 6th 2025 at 12:18

Outsourcing your helpdesk always seems like a good idea – until someone else's breach becomes your problem

Discord has confirmed customers' data was stolen – but says the culprit wasn't its own servers, just a compromised support vendor.…

☐ β˜† βœ‡ The Register - Security

Jaguar Land Rover engines ready to roar again after weeks-long cyber stall

β€” October 6th 2025 at 10:28

No confirmed date but workers expected to return in the coming days

Jaguar Land Rover is readying staff to resume manufacturing in the coming days, a company spokesperson confirmed to The Reg.…

☐ β˜† βœ‡ The Register - Security

Clop crew hits Oracle E-Business Suite users with fresh zero-day

β€” October 6th 2025 at 09:40

Big Red rushes out patch for 9.8-rated flaw after crooks exploit it for data theft and extortion

Oracle rushed out an emergency fix over the weekend for a zero-day vulnerability in its E-Business Suite (EBS) that criminal crew Clop has already abused for data theft and extortion.…

☐ β˜† βœ‡ The Register - Security

Leak suggests US government is fibbing over FEMA security failings

β€” October 6th 2025 at 08:55

Plus, PAN under attack, IT whistleblowers get a payout, and China kills online scammers

Infosec in brief On August 29, the US Federal Emergency Management Agency fired its CISO, CIO, and 22 other staff for incompetence but insisted it wasn't in response to an online attack. New material suggests FEMA's claim may be false.…

☐ β˜† βœ‡ The Register - Security

Red Hat fesses up to GitLab breach after attackers brag of data theft

β€” October 3rd 2025 at 14:42

Open source giant admits intruders broke into dedicated consulting instance, but insists core products untouched

What started as cyber crew bragging has now been confirmed by Red Hat: someone gained access to its consulting GitLab system and walked away with data.…

☐ β˜† βœ‡ The Register - Security

Apple ices ICE agent tracker app under government heat

β€” October 3rd 2025 at 13:49

Cupertino yanks ICEBlock citing safety risks for law enforcement

Apple has deep-sixed an app that tracks the movements of US Immigration and Customs Enforcement (ICE) agents – apparently bowing to government pressure.…

☐ β˜† βœ‡ The Register - Security

Munich Airport chaos after drone sightings spook air traffic control

β€” October 3rd 2025 at 12:58

Overnight shutdown leaves thousands stuck as Oktoberfest crowds stretch city security

Munich Airport was temporarily closed last night following reports of drones buzzing around the area.…

☐ β˜† βœ‡ The Register - Security

UK government says digital ID won't be compulsory – honest

β€” October 3rd 2025 at 12:05

Even spy-tech biz Palantir says 'steady on' as 2.76M Brits demand it be ditched

The British government has finally given more details about the proposed digital ID project, directly responding to the 2.76 million naysayers that signed an online petition calling for it to be ditched.…

☐ β˜† βœ‡ The Register - Security

Oracle tells Clop-targeted EBS users to apply July patch, problem solved

β€” October 3rd 2025 at 11:38

Researchers suggest internet-facing portals are exposing 'thousands' of orgs

Oracle has finally broken its silence on those Clop-linked extortion emails, but only to tell customers what they already should have known: patch your damn systems.…

☐ β˜† βœ‡ The Register - Security

Criminals take Renault UK customer data for a joyride

β€” October 3rd 2025 at 08:55

Names, numbers, and reg plates exposed in latest auto industry cyber-shunt

Renault UK customers are being warned their personal data may be in criminal hands after one of its supplier was hacked.…

☐ β˜† βœ‡ The Register - Security

Subpoena tracking platform blames outage on AWS social engineering attack

β€” October 2nd 2025 at 17:04

Software maker Kodex said its domain registrar fell for a fraudulent legal order

A software platform used by law enforcement agencies and major tech companies to manage subpoenas and data requests went dark this week after attackers socially engineered AWS into freezing its domain.…

☐ β˜† βœ‡ The Register - Security

Clop-linked crims shake down Oracle execs with data theft claims

β€” October 2nd 2025 at 12:45

Extortion emails name-drop Big Red's E-Business Suite, though Google and Mandiant yet to find proof of any breach

Criminals with potential links to the notorious Clop ransomware mob are bombarding Oracle execs with extortion emails, claiming to have stolen sensitive data from Big Red's E-Business Suite, according to researchers.…

☐ β˜† βœ‡ The Register - Security

EU funds are flowing into spyware companies, and politicians are demanding answers

β€” October 2nd 2025 at 12:02

Experts say Commission is β€˜fanning the flames’ of the continent’s own Watergate

An arsenal of angry European Parliament members (MEPs) is demanding answers from senior commissioners about why EU subsidies are ending up in the pockets of spyware companies.…

☐ β˜† βœ‡ The Register - Security

US gov shutdown leaves IT projects hanging, security defenders a skeleton crew

β€” October 1st 2025 at 19:48

The longer the shutdown, the less likely critical IT overhauls happen, ex federal CISO tells The Register

The US government shut down at 1201 ET on October 1, halting non-essential IT modernization and leaving cybersecurity operations to run on skeleton crews.…

☐ β˜† βœ‡ The Register - Security

Cybercrims claim raid on 28,000 Red Hat repos, say they have sensitive customer files

β€” October 2nd 2025 at 09:25

570GB of data claimed to be stolen by the Crimson Collective

A hacking crew claims to have broken into Red Hat's private GitLab repositories, exfiltrating some 570GB of compressed data, including sensitive documents belonging to customers. …

☐ β˜† βœ‡ The Register - Security

'Delightful' root-access bug in Red Hat OpenShift AI allows full cluster takeover

β€” October 1st 2025 at 19:35

Who wouldn't want root access on cluster master nodes?

A 9.9 out of 10 severity bug in Red Hat's OpenShift AI service could allow a remote attacker with minimal authentication to steal data, disrupt services, and fully hijack the platform.…

☐ β˜† βœ‡ The Register - Security

Air Force admits SharePoint privacy issue as reports trickle out of possible breach

β€” October 1st 2025 at 17:51

Uncle Sam can't quit Redmond

Exclusive The US Air Force confirmed it's investigating a "privacy-related issue" amid reports of a Microsoft SharePoint-related breach and subsequent service-wide shutdown, rendering mission files and other critical tools potentially unavailable to service members.…

☐ β˜† βœ‡ The Register - Security

3.7M breach notification letters set to flood North America's mailboxes

β€” October 1st 2025 at 12:24

Allianz Life and WestJet lead the way, along with a niche software shop

A trio of companies disclosed data breaches this week affecting approximately 3.7 million customers and employees across North America.…

☐ β˜† βœ‡ The Register - Security

AI agent hypefest crashing up against cautious leaders, Gartner finds

β€” October 1st 2025 at 11:25

Only 15% considering deployments and just 7% say it'll replace humans in next four years

Enterprises aren't keen on letting autonomous agents take the wheel amid fears over trust and security as research once again shows that AI hype is crashing against the rocks of reality.…

☐ β˜† βœ‡ The Register - Security

Imgur yanks Brit access to memes as parent company faces fine

β€” October 1st 2025 at 10:07

ICO investigation into platform's lack of age assurance continues

The UK's data watchdog has described Imgur's move to block UK users as "a commercial decision" after signaling plans to fine parent company MediaLab.…

☐ β˜† βœ‡ The Register - Security

Explain digital ID or watch it fizzle out, UK PM Starmer told

β€” October 1st 2025 at 09:13

Politico avoids the topic at Labour conference speech, homes in on AI instead

UK prime minister Keir Starmer avoided mentioning the mandatory digital ID scheme in his keynote speech to the Labour Party conference amid calls for him to put meat on the bones of the plans or risk it failing fast.…

☐ β˜† βœ‡ The Register - Security

Schools are swotting up on security yet still flunk recovery when cyberattacks strike

β€” October 1st 2025 at 08:50

Coursework 'gone forever' as 10% report critical damage

Schools and colleges hit by cyberattacks are taking longer to restore their networks β€” and the consequences are severe, with students' coursework being permanently lost in some cases.…

☐ β˜† βœ‡ The Register - Security

Beijing-backed burglars master .NET to target government web servers

β€” October 1st 2025 at 02:59

β€˜Phantom Taurus’ created custom malware to hunt secrets across Asia, Africa, and the Middle East

Threat-hunters at Palo Alto Networks’ Unit 42 have decided a gang they spotted two years ago is backed by China, after seeing it sling a new variety of malware.…

☐ β˜† βœ‡ The Register - Security

Fake North Korean IT workers sneaking into healthcare, finance, and AI

β€” September 30th 2025 at 22:20

It's not just big tech anymore

The North Korean IT worker threat extends well beyond tech companies, with fraudsters interviewing at a "surprising" number of healthcare orgs, according to Okta Threat Intelligence.…

☐ β˜† βœ‡ The Register - Security

Tile trackers are a stalker's dream, say Georgia Tech researchers

β€” September 30th 2025 at 21:32

Plaintext transmissions, fixed MAC addresses, rotating 'unique' IDs, and more, make abuse easy

Tile Bluetooth trackers leak identifying data in plain text, giving stalkers an easy way to track victims despite Life360's security promises, a group of Georgia Tech researchers warns.…

☐ β˜† βœ‡ The Register - Security

Google bolts AI into Drive to catch ransomware, but crooks not shaking yet

β€” September 30th 2025 at 20:10

Stopping the spread isn't the same as stopping attacks, period

Google on Tuesday rolled out a new AI tool in Drive for desktop that it says will pause syncing to limit ransomware damage, but it won't stop attacks outright.…

☐ β˜† βœ‡ The Register - Security

Warnings about Cisco vulns under active exploit are falling on deaf ears

β€” September 30th 2025 at 16:09

50,000 firewall devices still exposed

Nearly 50,000 Cisco ASA/FTD instances vulnerable to two bugs that are actively being exploited by "advanced" attackers remain exposed to the internet, according to Shadowserver data.…

☐ β˜† βœ‡ The Register - Security

TMI: How cloud collaboration suites drive oversharing and unmanaged access

β€” September 30th 2025 at 15:00

Sharing links take seconds to create, but can last for years

Partner Content Seamless collaboration through cloud platforms like Microsoft 365 has radically reshaped the modern workplace. In the span of an hour, you could go from uploading budget proposals to a project channel to live editing a joint presentation with a business partner, all while making lunch plans over Teams. From remote work to video calls, it’s never been easier to connect people, ideas, and information.…

☐ β˜† βœ‡ The Register - Security

Britain's policing minister punts facial recog nationwide

β€” September 30th 2025 at 10:01

Met's Croydon cameras hailed as a triumph, guidance to be published later this year

The government is to encourage police forces across England and Wales to adopt live facial recognition (LFR) technology, with a minister praising its use by the London's Metropolitan Police in a suburb in the south of the city.…

☐ β˜† βœ‡ The Register - Security

Β£5.5B Bitcoin fraudster pleads guilty after years on the run

β€” September 30th 2025 at 09:31

Zhimin Qian recruited takeaway worker to launder funds through property overseas

London's Metropolitan Police has secured a "landmark conviction" following a record-busting Bitcoin seizure and seven-year investigation.…

☐ β˜† βœ‡ The Register - Security

Greg Kroah-Hartman explains the Cyber Resilience Act for open source developers

β€” September 30th 2025 at 07:45

Impact? Nope, don't worry, be happy, says Linux veteran

Opinion There has been considerable worry about the impact of the European Union's Cyber Resilience Act on open source programmers. Linux stable kernel maintainer Greg Kroah-Hartman says, however, that there won't be much of an impact at all.…

❌