FreshRSS

πŸ”’
❌ Secure Planet Training Courses Updated For 2019 - Click Here
There are new available articles, click to refresh the page.
☐ β˜† βœ‡ The Register - Security

ShinyHunters 'does not like Salesforce at all,' claims the crew accessed Gainsight 3 months ago

β€” November 21st 2025 at 19:25

Shiny talks to The Reg

EXCLUSIVE ShinyHunters has claimed responsibility for the Gainsight breach that allowed the data thieves to snarf data from hundreds more Salesforce customers.…

☐ β˜† βœ‡ The Register - Security

Four charged over alleged plot to smuggle Nvidia AI chips into China

β€” November 21st 2025 at 13:58

Prosecutors say front companies, falsified paperwork, and overseas drop points used to dodge US export rules

Four people have been charged in the US with plotting to funnel restricted Nvidia AI chips into China, allegedly relying on shell firms, fake invoices, and covert routing to slip cutting-edge GPUs past American export controls.…

☐ β˜† βœ‡ The Register - Security

Russia-linked crooks bought a bank for Christmas to launder cyber loot

β€” November 21st 2025 at 13:15

UK cops trace street-level crime to sanctions-busting networks tied to Moscow's war economy

On Christmas Day 2024, a Russian-linked laundering network bought itself a very special present: a controlling stake in a Kyrgyzstan bank, later used to wash cybercrime profits and funnel money into Moscow's war machine, according to the UK's National Crime Agency (NCA).…

☐ β˜† βœ‡ The Register - Security

ZTE Launches ZXCSec MAF security solution for large model

β€” November 21st 2025 at 09:19

A multi-layered security framework protecting large-model applications from adversarial threats, data leakage, API abuse, and content risks

Partner Content At MWC Shanghai 2025, ZTE has officially launched its ZXCSec MAF product, a dedicated application-layer security protection device specifically designed for large model services.…

☐ β˜† βœ‡ The Register - Security

Google links Android’s Quick Share to Apple’s AirDrop, without Cupertino’s help

β€” November 21st 2025 at 03:55

Relies on very loose permissions, but don’t worry – Google wrote it in Rust

Google has linked Android’s wireless peer-to-peer file sharing tool Quick Share to Apple’s equivalent AirDrop.…

☐ β˜† βœ‡ The Register - Security

SEC drops SolarWinds lawsuit that painted a target on CISOs everywhere

β€” November 20th 2025 at 23:20

Company 'clearly delighted' with the outcome

The US Securities and Exchange Commission (SEC) has abandoned the lawsuit it pursued against SolarWinds and its chief infosec officer for misleading investors about security practices that led to the 2020 SUNBURST attack.…

☐ β˜† βœ‡ The Register - Security

Salesforce-linked data breach claims 200+ victims, has ShinyHunters’ fingerprints all over it

β€” November 20th 2025 at 20:30

They keep coming back for more

Salesforce has disclosed another third-party breach in which criminals - likely ShinyHunters (again) - may have accessed hundreds of its customers' data.…

☐ β˜† βœ‡ The Register - Security

LLM-generated malware is improving, but don't expect autonomous attacks tomorrow

β€” November 20th 2025 at 19:12

Researchers tried to get ChatGPT to do evil, but it didn't do a good job

LLMs are getting better at writing malware - but they're still not ready for prime time.…

☐ β˜† βœ‡ The Register - Security

Fired techie admits sabotaging ex-employer, causing $862K in damage

β€” November 20th 2025 at 16:44

PowerShell script locked thousands of workers out of their accounts

An Ohio IT contractor has pleaded guilty to breaking into his former employer's systems and causing nearly $1 million worth of damage after being fired.…

☐ β˜† βœ‡ The Register - Security

TP-Link accuses rival Netgear of 'smear campaign' over alleged China ties

β€” November 20th 2025 at 16:03

Networking vendor claims rival helped portray it as a national-security risk in the US

TP-Link is suing rival networking vendor Netgear, alleging that the rival and its CEO carried out a smear campaign by falsely suggesting, it says, that the biz had been infiltrated by the Chinese government.…

☐ β˜† βœ‡ The Register - Security

Education boards left gates wide open for PowerSchool mega-breach, say watchdogs

β€” November 20th 2025 at 14:46

Privacy cops say attack wasn't just bad luck but a result of sloppy homework

Canadian privacy watchdogs say that school boards must shoulder part of the blame for the PowerSchool mega-breach, not just the ed-tech giant that lost control of millions of student and staff records.…

☐ β˜† βœ‡ The Register - Security

Palo Alto kit sees massive surge in malicious activity amid mystery traffic flood

β€” November 20th 2025 at 11:38

GlobalProtect login endpoints targeted, sparking concern that something bigger may be brewing

Malicious traffic targeting Palo Alto Networks' GlobalProtect portals surged almost 40-fold in the space of 24 hours, hitting a 90-day high and putting defenders on alert for whatever comes next.…

☐ β˜† βœ‡ The Register - Security

Palo Alto CEO tips nation-states to weaponize quantum computing by 2029

β€” November 20th 2025 at 04:27

Company thinks you’ll contemplate replacing most security kit in the next few years to stay safe

Palo Alto Networks CEO Nikesh Arora has suggested hostile nation-states will possess quantum computers in 2029, or even a little earlier, at which point most security appliances will need to be replaced.…

☐ β˜† βœ‡ The Register - Security

US, UK, Australia sanction Lockbit gang’s hosting provider

β€” November 20th 2025 at 01:30

β€˜Bulletproof’ hosts partly dodged the last attack of this sort

Cybercrime fighters in the US, UK, and Australia have imposed sanctions on several Russia-linked entities they claim provide hosting services to ransomware gangs Lockbit, BlackSuit, and Play.…

☐ β˜† βœ‡ The Register - Security

Fortinet 'fesses up to second 0-day within a week

β€” November 19th 2025 at 23:07

Attackers may be joining the dots to enable unauthenticated RCE

Fortinet has confirmed that another flaw in its FortiWeb web application firewall has been exploited as a zero-day and issued a patch, just days after disclosing a critical bug in the same product that attackers had found and abused a month earlier.…

☐ β˜† βœ‡ The Register - Security

Amazon security boss: Hostile countries use cyber targeting for physical military strikes

β€” November 19th 2025 at 18:26

And companies are getting caught in the crossfire

interview Warfare has become a joint cyber-kinetic endeavor, with nations using cyber operations to scope out targets before launching missiles. And private companies, including shipping, transportation, and electronics manufacturers, are getting caught in the crossfire, according to Amazon.…

☐ β˜† βœ‡ The Register - Security

Researchers claim 'largest leak ever' after uncovering WhatsApp enumeration flaw

β€” November 19th 2025 at 13:16

Two-day exploit opened up 3.5 billion users to myriad potential harms

Researchers in Austria used a flaw in WhatsApp to gather the personal data of more than 3.5 billion users in what they believe amounts to the "largest data leak in history."…

☐ β˜† βœ‡ The Register - Security

Tens of thousands more ASUS routers pwned by suspected, evolving China operation

β€” November 19th 2025 at 09:30

Researchers say attacks are laying the groundwork for stealthy espionage activity

Around 50,000 ASUS routers have been compromised in a sophisticated attack that researchers believe may be linked to China, according to findings released today by SecurityScorecard's STRIKE team.…

☐ β˜† βœ‡ The Register - Security

Selling technology investments to the board: a strategic guide for CISOs and CIOs

β€” November 19th 2025 at 09:00

The C-suite will have zero interest in zero trust without a good business case

Partner Content In today's enterprise environment, technology investments are no longer judged solely by their technical sophistication. Approval depends on their ability to support business goals, mitigate risk, and create value for shareholders. CIOs and CISOs are expected to present their strategies not as technical upgrades but as business enablers. The challenge is not just making the right investments, but framing them in ways that resonate at the boardroom level.…

☐ β˜† βœ‡ The Register - Security

China recruiting spies in the UK with fake headhunters and β€˜sites like LinkedIn’

β€” November 19th 2025 at 05:37

MI5 sounds the alarm about attempts to source sensitive information

Chinese spies are using social media and fake recruitment agents to recruit sources with access to sensitive information in the UK.…

☐ β˜† βœ‡ The Register - Security

Self-replicating botnet attacks Ray clusters

β€” November 18th 2025 at 21:43

Using AI to attack AI

updated Malefactors are actively attacking internet-facing Ray clusters and abusing the open source AI framework to spread a self-replicating botnet that mines for cryptocurrency, steals data, and launches distributed denial of service (DDoS) attacks.…

☐ β˜† βœ‡ The Register - Security

FCC looks to torch Biden-era cyber rules sparked by Salt Typhoon mess

β€” November 18th 2025 at 18:16

Regulator sides with telcos that claimed new cybersecurity duties were too β€˜burdensome’

The Federal Communications Commission (FCC) will vote this week on whether to scrap Biden-era cybersecurity rules, enacted after the Salt Typhoon attacks came to light in 2024, that required telecom carriers to adopt basic security controls.…

☐ β˜† βœ‡ The Register - Security

Take fight to the enemy, US cyber boss says

β€” November 18th 2025 at 17:48

When? Sean Cairncross wouldn't say

America is fed up with being the prime target for foreign hackers. So US National Cyber Director Sean Cairncross says Uncle Sam is going on the offensive – he just isn't saying when.…

☐ β˜† βœ‡ The Register - Security

Google Chrome bug exploited as an 0-day - patch now or risk full system compromise

β€” November 18th 2025 at 17:43

Seventh Chrome 0-day this year

Google pushed an emergency patch on Monday for a high-severity Chrome bug that attackers have already found and exploited in the wild.…

☐ β˜† βœ‡ The Register - Security

Zoomers are officially worse at passwords than 80-year-olds

β€” November 18th 2025 at 12:50

They can probably set up a printer faster, but look elsewhere for cryptography advice

Gen Z can get off their digital high horses because their passwords are no more secure than their grandparents'.…

☐ β˜† βœ‡ The Register - Security

'Largest-ever' cloud DDoS attack pummels Azure with 3.64B packets per second

β€” November 17th 2025 at 21:54

Aisuru botnet strikes again, bigger and badder

Azure was hit by the "largest-ever" cloud-based distributed denial of service (DDoS) attack, originating from the Aisuru botnet and measuring 15.72 terabits per second (Tbps), according to Microsoft.…

☐ β˜† βœ‡ The Register - Security

Pentagon and soldiers let too many secrets slip on social networks, watchdog says

β€” November 17th 2025 at 21:32

Ready, aim, mire

Loose lips sink ships, the classic line goes. Information proliferation in the internet age has government auditors reiterating that loose tweets can sink fleets, and they're concerned that the Defense Department isn't doing enough to stop sensitive info from getting out there. …

☐ β˜† βœ‡ The Register - Security

Security researcher calls BS on Coinbase breach disclosure timeline

β€” November 17th 2025 at 19:47

Claims he reported the attack in January after fraudsters tried to scam him

A security researcher says Coinbase knew about a December 2024 security breach during which miscreants bribed its support staff into handing over almost 70,000 customers' details at least four months before it disclosed the data theft.…

☐ β˜† βœ‡ The Register - Security

Selling your identity to North Korean IT scammers isn't a sustainable side hustle

β€” November 17th 2025 at 17:25

Four US citizens tried it, and the DoJ just secured guilty pleas from all of 'em

It sounds like easy money. North Koreans pay you to use your identity so they can get jobs working for American companies in IT. However, if you go this route, the US Department of Justice promises to catch up with you eventually.…

☐ β˜† βœ‡ The Register - Security

Game over: Europol storms gaming platforms in extremist content sweep

β€” November 17th 2025 at 15:38

Law enforcement agency’s referral blitz hit gaming platforms hard, surfacing thousands of extremist URLs

Europol's Internet Referral Unit (EU IRU) says a November 13 operation across gaming and "gaming-adjacent" services led its partners to report thousands of URLs hosting terrorist and hate-fueled material, including 5,408 links to jihadist content, 1,070 pushing violent right-wing extremist or terrorist propaganda, and 105 tied to racist or xenophobic groups.…

☐ β˜† βœ‡ The Register - Security

Overconfidence is the new zero-day as teams stumble through cyber simulations

β€” November 17th 2025 at 15:00

Readiness metrics have flatlined since 2023, with most sectors slipping backward as teams fumble crisis drills

Teams that think they're ready for a major cyber incident are scoring barely 22 percent accuracy and taking more than a day to contain simulated attacks, according to new data out Monday.…

☐ β˜† βœ‡ The Register - Security

Eurofiber admits crooks swiped data from French unit after cyberattack

β€” November 17th 2025 at 12:44

Regulator reports suggest telco was extorted, but company remains coy as to whether it paid

French telco Eurofiber says cybercriminals swiped company data during an attack last week that also affected some internal systems.…

☐ β˜† βœ‡ The Register - Security

UK prosecutors seize Β£4.11M in crypto from Twitter mega-hack culprit

β€” November 17th 2025 at 11:56

Civil recovery order targets PlugwalkJoe's illicit gains while he serves US sentence

British prosecutors have secured a civil recovery order to seize crypto assets worth Β£4.11 million ($5.39 million) from Twitter hacker Joseph James O'Connor, clawing back the proceeds of a scam that used hijacked celebrity accounts to solicit digital currency and threaten high-profile individuals.…

☐ β˜† βœ‡ The Register - Security

Jaguar Land Rover hack cost India's Tata Motors around $2.4 billion and counting

β€” November 17th 2025 at 01:41

PLUS: Active noise cancellation for entire rooms; More trouble for Korea Telecom; The Wiggles apologize for bad batteries; and more

Asia In Brief India’s Tata Motors, owner of Jaguar Land Rover, has revealed the cyberattack that shut down production in the UK has so far cost it around Β£1.8 billion ($2.35 billion).…

☐ β˜† βœ‡ The Register - Security

Logitech leaks data after zero-day attack

β€” November 16th 2025 at 23:05

PLUS: CISA still sitting on telecoms security report; DoorDash phished again; Lumma stealer returns; and more

INFOSEC IN BRIEF The US Senate passed a resolution in July to force the US Cybersecurity and Infrastructure Security Agency (CISA) to publish a 2022 report into poor security in the telecommunications industry but the agency has not delivered the document.…

☐ β˜† βœ‡ The Register - Security

Fortinet finally cops to critical make-me-admin bug under active exploitation

β€” November 14th 2025 at 20:39

More than a month after PoC made public

Fortinet finally published a security advisory on Friday for a critical FortiWeb path traversal vulnerability under active exploitation – but it appears digital intruders got a month's head start.…

☐ β˜† βœ‡ The Register - Security

Crims poison 150K+ npm packages with token-farming malware

β€” November 14th 2025 at 18:22

Amazon spilled the TEA

Yet another supply chain attack has hit the npm registry in what Amazon describes as "one of the largest package flooding incidents in open source registry history" - but with a twist. Instead of injecting credential-stealing code or ransomware into the packages, this one is a token farming campaign.…

☐ β˜† βœ‡ The Register - Security

FBI flags scam targeting Chinese speakers with bogus surgery bills

β€” November 14th 2025 at 16:16

Crooks spoof US insurers, threaten bogus extradition to pry loose personal data and cash

Chinese speakers in the US are being targeted as part of an aggressive health insurance scam campaign, the FBI warns.…

☐ β˜† βœ‡ The Register - Security

CISA flags imminent threat as Akira ransomware starts hitting Nutanix AHV

β€” November 14th 2025 at 15:02

Advisory updated as leading cybercrime crew opens up its target pool

The US Cybersecurity and Infrastructure Security Agency (CISA) has issued new guidance to organizations on the Akira ransomware operation, which poses an imminent threat to critical sectors.…

☐ β˜† βœ‡ The Register - Security

Clop claims it hacked 'the NHS.' Which bit? Your guess is as good as theirs

β€” November 14th 2025 at 09:30

Cybercrime crew has ravaged multiple private organizations using Oracle EBS zero-day for months

The UK's National Health Service (NHS) is investigating claims of a cyberattack by extortion crew Clop.…

☐ β˜† βœ‡ The Register - Security

Kubernetes overlords decide Ingress NGINX isn’t worth saving

β€” November 14th 2025 at 01:12

Maintenance to end next year after β€˜helpful options’ became β€˜serious security flaws’

Kubernetes maintainers have decided it’s not worth trying to save Ingress NGINX and will instead stop work on the project and retire it in March 2026.…

☐ β˜† βœ‡ The Register - Security

Chinese spies told Claude to break into about 30 critical orgs. Some attacks succeeded

β€” November 13th 2025 at 23:12

Anthropic dubs this the first AI-orchestrated cyber snooping campaign

Chinese cyber spies used Anthropic's Claude Code AI tool to attempt digital break-ins at about 30 high-profile companies and government organizations – and the government-backed snoops "succeeded in a small number of cases," according to a Thursday report from the AI company.…

☐ β˜† βœ‡ The Register - Security

Ransomed CTO falls on sword, refuses to pay extortion demand

β€” November 13th 2025 at 20:02

Checkout.com will instead donate the amount to fund cybercrime research

Digitial extortion is a huge business, because affected orgs keep forking over money to get their data back. However, instead of paying a ransom demand after getting hit by extortionists last week, payment services provider Checkout.com donated the demanded amount to fund cybercrime research.…

☐ β˜† βœ‡ The Register - Security

Ubuntu 25.10's Rusty sudo holes quickly welded shut

β€” November 13th 2025 at 15:45

The goal of 'oxidizing' the Linux distro hits another bump

Two vulnerabilities in Ubuntu 25.10's new "sudo-rs" command have been found, disclosed, and fixed in short order.…

☐ β˜† βœ‡ The Register - Security

Extra, extra, read all about it: Washington Post clobbered in Clop caper

β€” November 13th 2025 at 13:45

Nearly 10,000 staff and contractors warned after attackers raided newspaper's Oracle EBS setup

The Washington Post has confirmed that nearly 10,000 employees and contractors had sensitive personal data stolen in the Clop-linked Oracle E-Business Suite (EBS) attacks.…

☐ β˜† βœ‡ The Register - Security

Rhadamanthys malware admin rattled as cops seize a thousand-plus servers

β€” November 13th 2025 at 12:01

Operation Endgame also takes down Elysium and VenomRAT infrastructure

International cops have pulled apart the Rhadamanthys infostealer operation, seizing 1,025 servers tied to the malware in coordinated raids between November 10-13.…

☐ β˜† βœ‡ The Register - Security

NHS supplier ends probe into ransomware attack that contributed to patient death

β€” November 13th 2025 at 11:13

Synnovis's 18-month forensic review of Qilin intrusion completed, now affected patients to be notified

Synnovis has finally wrapped up its investigation into the 2024 ransomware attack that crippled pathology services across London, ending an 18-month effort to untangle what the NHS supplier describes as one of the most complex data reconstruction jobs it has ever faced.…

☐ β˜† βœ‡ The Register - Security

Google sues 25 China-based scammers behind Lighthouse 'phishing for dummies' kit

β€” November 12th 2025 at 21:39

600+ phishing websites and 116 of these use a Google logo

Google has filed a lawsuit against 25 unnamed China-based scammers, which it claims have stolen more than 115 million credit card numbers in the US as part of the Lighthouse phishing operation.…

☐ β˜† βœ‡ The Register - Security

Attackers turned Citrix, Cisco 0-day exploits into custom-malware hellscape

β€” November 12th 2025 at 17:16

Vendors (still) keep mum

An "advanced" attacker exploited CitrixBleed 2 and a max-severity Cisco Identity Services Engine (ISE) bug as zero-days to deploy custom malware, according to Amazon Chief Information Security Officer CJ Moses.…

☐ β˜† βœ‡ The Register - Security

Bitcoin bandit's Β£5B bubble bursts as cops wrap seven-year chase

β€” November 12th 2025 at 11:21

Metropolitan Police lands lengthy sentence following 'complex' investigation

The Metropolitan Police's seven-year investigation into a record-setting fraudster has ended after she was sentenced to 11 years and eight months in prison on Tuesday.…

☐ β˜† βœ‡ The Register - Security

UK's Cyber Security and Resilience Bill makes Parliamentary debut

β€” November 12th 2025 at 10:54

Various touch-ups added as MPs seek greater resilience to attacks on critical sectors

UK government introduced the Cyber Security and Resilience (CSR) Bill to Parliament today, marking a significant overhaul of local cybersecurity legislation to sharpen the security posture of the most critical sectors.…

☐ β˜† βœ‡ The Register - Security

Aviation watchdog says organized drone attacks will shut UK airports β€˜sooner or later’

β€” November 12th 2025 at 10:15

Skies are open for mischief as hard-to-trace drones and fast-moving cyber raids promise new wave of disruption

Britain's aviation watchdog has warned it's only a matter of time before organized drone attacks bring UK airports to a standstill.…

☐ β˜† βœ‡ The Register - Security

China hates crypto and scams, but is now outraged USA acquired bitcoin from a scammer

β€” November 12th 2025 at 04:47

A new theory from the agency that brought us β€˜America hacked itself to blame Beijing’

China’s National Computer Virus Emergency Response Center (CVERC) has alleged a nation-state entity, probably the USA, was behind a 2020 attack on a bitcoin mining operation and by doing so has gone into bat for entities that Beijing usually blasts.…

☐ β˜† βœ‡ The Register - Security

Australia’s spy boss says authoritarian nations ready to commit β€˜high-impact sabotage’

β€” November 12th 2025 at 01:17

β€˜Elite teams’ are pondering cyber-attacks to turn off energy supply or telecoms networks

The head of Australia’s Security Intelligence Organisation (ASIO) has warned that authoritarian regimes β€œare growing more willing to disrupt or destroy critical infrastructure”, using cyber-sabotage.…

☐ β˜† βœ‡ The Register - Security

North Korean spies turn Google's Find Hub into remote-wipe weapon

β€” November 11th 2025 at 16:26

KONNI espionage crew covertly abused Google’s Find My Device feature to remotely factory-reset Android phones

North Korean state-backed spies have found a new way to torch evidence of their own cyber-spying – by hijacking Google's Find Hub service to remotely wipe Android phones belonging to their South Korean targets.…

☐ β˜† βœ‡ The Register - Security

EU's reforms of GDPR, AI slated by privacy activists for 'playing into Big Tech’s hands'

β€” November 11th 2025 at 14:30

Lobbying efforts gain ground as proposals carve myriad holes into regulations

Privacy advocates are condemning the European Commission's leaked plans to overhaul digital privacy legislation, accusing officials of bypassing proper legislative processes to favor Big Tech interests.…

☐ β˜† βœ‡ The Register - Security

OWASP Top 10: Broken access control still tops app security list

β€” November 11th 2025 at 13:26

Risk list highlights misconfigs, supply chain failures, and singles out prompt injection in AI apps

The Open Worldwide Application Security Project (OWASP) just published its top 10 categories of application risks for 2025, its first list since 2021. It found that while broken access control remains the top issue, security misconfiguration is a strong second, and software supply chain issues are still prominent.…

☐ β˜† βœ‡ The Register - Security

Hitachi-owned GlobalLogic admits data stolen on 10k current and former staff

β€” November 11th 2025 at 12:20

Clop's Oracle EBS exploit spree shows no sign of slowing, claims nearly 30 more casualties in media, finance, and tech.

Digital engineering outfit GlobalLogic says personal data from more than 10,000 current and former employees was exposed in the wave of Oracle E-Business Suite (EBS) attacks attributed to the Clop ransomware gang. The Hitachi-owned biz joins a growing roster of high-profile victims that also now includes The Washington Post and Allianz UK.…

☐ β˜† βœ‡ The Register - Security

UK asks cyberspies to probe whether Chinese buses can be switched off remotely

β€” November 11th 2025 at 11:55

Norwegian testers claim maker has remote access, while UK importer says supplier complies with the law

UK governmental is working with the National Cyber Security Centre to understand and "mitigate" any risk that China-made imported electric buses could be remotely accessed and potentially disabled.…

☐ β˜† βœ‡ The Register - Security

Cyber insurers paid out over twice as much for UK ransomware attacks last year

β€” November 11th 2025 at 11:04

Massive increase in policy claims… and data doesn’t even cover the major attacks of 2025

The number of successful cyber insurance claims made by UK organizations shot up last year, according to the latest figures from the industry's trade association.…

❌