FreshRSS

πŸ”’
❌ Secure Planet Training Courses Updated For 2019 - Click Here
There are new available articles, click to refresh the page.
☐ β˜† βœ‡ The Register - Security

British IT worker sentenced to seven months after trashing company network

β€” June 30th 2025 at 18:29

Don't leave the door open to disgruntled workers

A judge has sentenced a disgruntled IT worker to more than seven months in prison after he wreaked havoc on his employer's network following his suspension, according to West Yorkshire Police.…

☐ β˜† βœ‡ The Register - Security

Scattered Spider crime spree takes flight as focus turns to aviation sector

β€” June 30th 2025 at 17:31

Time ticking for defenders as social engineering pros weave wider web

Just a few weeks after warning about Scattered Spider's tactics shifting toward the insurance industry, the same experts now say the aviation industry is now on the ransomware crew's radar.…

☐ β˜† βœ‡ The Register - Security

Sinaloa drug cartel hired a cybersnoop to identify and kill FBI informants

β€” June 30th 2025 at 13:13

Device compromises and deep-seated access to critical infrastructure exposed surveillance vulnerabilities in agency's work

A major Mexican drug cartel insider grassed on his fellow drug-peddlers back in 2018, telling the FBI that a cartel "hacker" was tracking a federal official and using their deep-rooted access to the country's critical infrastructure to kill informants.…

☐ β˜† βœ‡ The Register - Security

Your browser has ad tech's fingerprints all over it, but there's a clean-up squad in town

β€” June 30th 2025 at 08:33

Like being hard to spot? They’d much rather you didn’t

Opinion There are few tech deceptions more successful than Chrome's Incognito Mode.…

☐ β˜† βœ‡ The Register - Security

Canada orders Chinese CCTV biz Hikvision to quit the country ASAP

β€” June 30th 2025 at 03:26

PLUS: Broadband blimps to fly in Japan; Starbucks China put ads before privacy; and more!

Asia In Brief Canada’s government has ordered Chinese CCTV systems vendor Hikvision to cease its local operations.…

☐ β˜† βœ‡ The Register - Security

It's 2025 and almost half of you are still paying ransomware operators

β€” June 30th 2025 at 00:34

PLUS: Crooks target hardware crypto wallets; Bad flaws in Brother printers; ,O365 allows takeover-free phishing; and more

Infosec in Brief Despite warnings not to pay ransomware operators, almost half of those infected by the malware send cash to the crooks who planted it, according to infosec software slinger Sophos.…

☐ β˜† βœ‡ The Register - Security

Ex-NATO hacker: 'In the cyber world, there's no such thing as a ceasefire'

β€” June 28th 2025 at 14:01

Watch out for supply chain hacks especially

interview The ceasefire between Iran and Israel may prevent the two countries from firing missiles at each other, but it won't carry any weight in cyberspace, according to former NATO hacker Candan Bolukbas.…

☐ β˜† βœ‡ The Register - Security

Crims are posing as insurance companies to steal health records and payment info

β€” June 27th 2025 at 22:59

Taking advantage of the ridiculously complex US healthcare billing system

Criminals masquerading as insurers are tricking patients and healthcare providers into handing over medical records and bank account information via emails and text messages, according to the FBI.…

☐ β˜† βœ‡ The Register - Security

Cisco punts network-security integration as key for agentic AI

β€” June 27th 2025 at 17:29

Getting it in might mean re-racking the entire datacenter and rebuilding the network, though

Cisco is talking up the integration of security into network infrastructure such as its latest Catalyst switches, claiming this is vital to AI applications, and in particular the current vogue for "agentic AI."…

☐ β˜† βœ‡ The Register - Security

Aloha, you’ve been pwned: Hawaiian Airlines discloses β€˜cybersecurity event’

β€” June 27th 2025 at 16:56

'No impact on safety,' FAA tells The Reg

update Hawaiian Airlines said a "cybersecurity incident" affected some of its IT systems, but noted that flights are operating as scheduled. At least one researcher believes Scattered Spider, which previously targeted retailers and insurance companies, could be to blame.…

☐ β˜† βœ‡ The Register - Security

So you CAN turn an entire car into a video game controller

β€” June 27th 2025 at 15:27

Pen Test Partners hijack data from Renault Clio to steer, brake, and accelerate in SuperTuxKart

Cybersecurity nerds figured out a way to make those at-home racing simulators even more realistic by turning an actual car into a game controller.…

☐ β˜† βœ‡ The Register - Security

Data spill in aisle 5: Grocery giant Ahold Delhaize says 2.2M affected after cyberattack

β€” June 27th 2025 at 13:39

Finance, health, and national identification details compromised

Multinational grocery and retail megacorp Ahold Delhaize says upwards of 2.2 million people had their data compromised during its November cyberattack with personal, financial and health details among the trove.…

☐ β˜† βœ‡ The Register - Security

FBI used bitcoin wallet records to peg notorious IntelBroker as UK national

β€” June 26th 2025 at 19:02

Pro tip: Don't use your personal email account on BreachForums

The notorious data thief known as IntelBroker allegedly broke into computer systems belonging to more than 40 victims worldwide and stole their data, costing them at least $25 million in damages, according to newly unsealed court documents that also name IntelBroker as 25-year-old British national Kai West.…

☐ β˜† βœ‡ The Register - Security

What if Microsoft just turned you off? Security pro counts the cost of dependency

β€” June 26th 2025 at 18:34

Czech researcher lays out a business case for reducing reliance on Redmond

Comment A sharply argued blog post warns that heavy reliance on Microsoft poses serious strategic risks for organizations – a viewpoint unlikely to win favor with Redmond or its millions of corporate customers.…

☐ β˜† βœ‡ The Register - Security

Cisco fixes two critical make-me-root bugs on Identity Services Engine components

β€” June 26th 2025 at 17:30

A 10.0 and a 9.8 – these aren’t patches to dwell on

Cisco has dropped patches for a pair of critical vulnerabilities that could allow unauthenticated remote attackers to execute code on vulnerable systems.…

☐ β˜† βœ‡ The Register - Security

Glasgow City Council online services crippled following cyberattack

β€” June 26th 2025 at 12:01

Nothing confirmed but authority is operating under the assumption that data has been stolen

A cyberattack on Glasgow City Council is causing massive disruption with a slew of its digital services unavailable.…

☐ β˜† βœ‡ The Register - Security

Qilin ransomware attack on NHS supplier contributed to patient fatality

β€” June 26th 2025 at 11:02

Pathology outage caused by Synnovis breach linked to harm across dozens of healthcare facilities

The NHS says Qilin's ransomware attack on pathology services provider Synnovis last year led to the death of a patient.…

☐ β˜† βœ‡ The Register - Security

UK to buy nuclear-capable F-35As that can't be refueled from RAF tankers

β€” June 26th 2025 at 09:14

Aircraft meant to bolster NATO deterrent will rely on allied support to stay airborne

The UK government is to buy 12 F-35A fighters capable of carrying nuclear weapons as part of the NATO deterrent, but there's a snag: the new jets are incompatible with the RAF's refueling tanker aircraft.…

☐ β˜† βœ‡ The Register - Security

Frozen foods supermarket chain deploys facial recognition tech

β€” June 26th 2025 at 08:30

Privacy campaigner brands Iceland's use of 'Orwellian' camera tech 'chilling,' CEO responds: 'It'll cut violent crime'

Privacy campaigners are branding frozen food retailer Iceland's decision to trial facial recognition technology (FRT) at several stores "chilling" – the UK supermarket chain says it's deploying the cameras to cut down on crime.…

☐ β˜† βœ‡ The Register - Security

That WhatsApp from an Israeli infosec expert could be a Iranian phish

β€” June 26th 2025 at 06:28

Charming Kitten unsheathes its claws and tries to catch credentials

The cyber-ops arm of Iran's Islamic Revolutionary Guard Corps has started a spear-phishing campaign intent on stealing credentials from Israeli journalists, cybersecurity experts, and computer science professors from leading Israeli universities.…

☐ β˜† βœ‡ The Register - Security

Citrix bleeds again: This time a zero-day exploited - patch now

β€” June 25th 2025 at 21:10

Two emergency patches issued in two weeks

Hot on the heels of patching a critical bug in Citrix-owned Netscaler ADC and NetScaler Gateway that one security researcher dubbed "CitrixBleed 2," the embattled networking device vendor today issued an emergency patch for yet another super-serious flaw in the same products β€” but not before criminals found and exploited it as a zero-day.…

☐ β˜† βœ‡ The Register - Security

Amazon's Ring can now use AI to 'learn the routines of your residence'

β€” June 25th 2025 at 19:02

It's meant to cut down on false positives but could be a trove for mischief-makers

Ring doorbells and cameras are using AI to "learn the routines of your residence," via a new feature called Video Descriptions.…

☐ β˜† βœ‡ The Register - Security

Computer vision research feeds surveillance tech as patent links spike 5Γ—

β€” June 25th 2025 at 17:55

A bottomless appetite for tracking people as 'objects'

A new study shows academic computer vision papers feeding surveillance-enabling patents jumped more than fivefold from the 1990s to the 2010s.…

☐ β˜† βœ‡ The Register - Security

Supply chain attacks surge with orgs 'flying blind' about dependencies

β€” June 25th 2025 at 17:36

Who is the third party that does the thing in our thing? Yep. Attacks explode over past year

The vast majority of global businesses are handling at least one material supply chain attack per year, but very few are doing enough to counter the growing threat.…

☐ β˜† βœ‡ The Register - Security

French cybercrime police arrest five suspected BreachForums admins

β€” June 25th 2025 at 15:34

Twentysomethings claimed to be linked to spate of high-profile cybercrimes

The Paris police force's cybercrime brigade (BL2C) has arrested a further four men as part of a long-running investigation into the criminals behind BreachForums.…

☐ β˜† βœ‡ The Register - Security

UK govt dept website that campaigns against encryption hijacked to advertise ... payday loans

β€” June 25th 2025 at 09:26

Company at center of findings blamed SEO on outsourcer

A website developed for the UK Home Office's 2022 "flop" anti-encryption campaign has seemingly been hijacked to push a payday loan scheme.…

☐ β˜† βœ‡ The Register - Security

Don't panic, but it's only a matter of time before critical 'CitrixBleed 2' is under attack

β€” June 24th 2025 at 21:01

Why are you even reading this story? Patch now!

Citrix patched a critical vulnerability in its NetScaler ADC and NetScaler Gateway products that is already being compared to the infamous CitrixBleed flaw exploited by ransomware gangs and other cyber scum, although there haven't been any reports of active exploitation. Yet.…

☐ β˜† βœ‡ The Register - Security

Beware of fake SonicWall VPN app that steals users' credentials

β€” June 24th 2025 at 17:22

A good reminder not to download apps from non-vendor sites

Unknown miscreants are distributing a fake SonicWall app to steal users' VPN credentials.…

☐ β˜† βœ‡ The Register - Security

The vulnerability management gap no one talks about

β€” June 24th 2025 at 15:01

If an endpoint goes ping but isn't on the network, does anyone hear it?

Partner content Recently, I've been diving deep into security control data across dozens of organizations, and what I've found has been both fascinating and alarming. Most security teams I work with can rattle off their vulnerability management statistics with confidence. They know their scan schedules, their remediation timelines, and their critical vulnerability counts. They point to clean dashboards and comprehensive reports as proof that their programs are working.…

☐ β˜† βœ‡ The Register - Security

Four REvil ransomware crooks walk free, escape gulag fate, after admitting guilt

β€” June 24th 2025 at 11:46

Russian judge lets off accused with time served – but others who refused to plead guilty face years in penal colony

Four convicted members of the once-supreme ransomware operation REvil are leaving captivity after completing most of their five-year sentences.…

☐ β˜† βœ‡ The Register - Security

Psylo browser tries to obscure digital fingerprints by giving every tab its own IP address

β€” June 24th 2025 at 06:32

Gotta keep 'em separated so the marketers and snoops can't come out and play

Psylo, which bills itself as a new kind of private web browser, debuted last Tuesday in Apple's App Store, one day ahead of a report warning about the widespread use of browser fingerprinting for ad tracking and targeting.…

☐ β˜† βœ‡ The Register - Security

Typhoon-like gang slinging TLS certificate 'signed' by the Los Angeles Police Department

β€” June 23rd 2025 at 23:45

Chinese crew built 1,000+ device network that runs on home devices then targets critical infrastructure

A stealthy, ongoing campaign to gain long-term access to networks bears all the markings of intrusions conducted by China’s β€˜Typhoon’ crews and has infected at least 1,000 devices, primarily in the US and South East, according to SecurityScorecard's Strike threat intel analysts. And it uses a phony certificate purportedly signed by the Los Angeles police department to try and gain access to critical infrastructure.…

☐ β˜† βœ‡ The Register - Security

Iran cyberattacks against US biz more likely following air strikes

β€” June 23rd 2025 at 18:41

Plus 'low-level' hacktivist attempts

The US Department of Homeland Security has warned American businesses to guard their networks against Iranian government-sponsored cyberattacks along with "low-level" digital intrusions by pro-Iran hacktivists.…

☐ β˜† βœ‡ The Register - Security

Second attack on McLaren Health Care in a year affects 743k people

β€” June 23rd 2025 at 15:48

Criminals targeted the hospital and physician network’s Detroit cancer clinic this time

McLaren Health Care is in the process of writing to 743,131 individuals now that it fully understands the impact of its July 2024 cyberattack.…

☐ β˜† βœ‡ The Register - Security

Experts count staggering costs incurred by UK retail amid cyberattack hell

β€” June 23rd 2025 at 11:29

Cyber Monitoring Centre issues first severity assessment since February launch

Britain's Cyber Monitoring Centre (CMC) estimates the total cost of the cyberattacks that crippled major UK retail organizations recently could be in the region of Β£270-440 million ($362-591 million).…

☐ β˜† βœ‡ The Register - Security

Former US Army Sergeant pleads guilty after amateurish attempt at selling secrets to China

β€” June 23rd 2025 at 00:33

PLUS: 5.4M healthcare records leak; AI makes Spam harder to spot; Many nasty Linux vulns; and more

Infosec in brief A former US Army sergeant has admitted he attempted to sell classified data to China.…

☐ β˜† βœ‡ The Register - Security

Netflix, Apple, BofA websites hijacked with fake help-desk numbers

β€” June 20th 2025 at 21:10

Don’t trust mystery digits popping up in your search bar

Scammers are hijacking the search results of people needing 24/7 support from Apple, Bank of America, Facebook, HP, Microsoft, Netflix, and PayPal in an attempt to trick victims into handing over personal or financial info, according to Malwarebytes senior director of research JΓ©rΓ΄me Segura.…

☐ β˜† βœ‡ The Register - Security

Looks like Aflac is the latest insurance giant snagged in Scattered Spider’s web

β€” June 20th 2025 at 17:55

If it looks like a duck and walks like a duck...

Aflac is the latest insurance company to disclose a security breach following a string of others earlier this week, all of which appear to be part of Scattered Spider's most recent data theft campaign.…

☐ β˜† βœ‡ The Register - Security

Qilin ransomware top dogs treat their minions to on-call lawyers for fierier negotiations

β€” June 20th 2025 at 17:31

It's a marketing move to lure more affiliates, says infosec veteran

The latest marketing ploy from the ransomware crooks behind the Qilin operation involves offering affiliates access to a crack team of lawyers to ramp up pressure in ransom negotiations.…

☐ β˜† βœ‡ The Register - Security

Attack on Oxford City Council exposes 21 years of election worker data

β€” June 20th 2025 at 10:45

Services coming back online after legacy systems compromised

Oxford City Council says a cyberattack earlier this month resulted in 21 years of data being compromised.…

☐ β˜† βœ‡ The Register - Security

Boffins devise voice-altering tech to jam 'vishing' schemes

β€” June 19th 2025 at 19:25

To stop AI scam callers, break automatic speech recognition systems

Researchers based in Israel and India have developed a defense against automated call scams.…

☐ β˜† βœ‡ The Register - Security

Uncle Sam seeks time in tower dump data grab case after judge calls it 'unconstitutional'

β€” June 19th 2025 at 16:30

Feds told they can't demand a haystack to find a needle

The United States is requesting [PDF] a month-long extension to the deadline for its final decision regarding an appeal against a judge's ruling that obtaining tower dumps is unconstitutional.…

☐ β˜† βœ‡ The Register - Security

Glazed and confused: Hole lotta highly sensitive data nicked from Krispy Kreme

β€” June 19th 2025 at 13:29

Experts note 'major red flags' in donut giant's security as 161,676 staff and families informed of attack details

Krispy Kreme finally revealed the number of people affected by its November cyberattack, and it's easy to see why analyzing the incident took the well-resourced company several months.…

☐ β˜† βœ‡ The Register - Security

UK gov asks university boffins to pinpoint cyber growth areas where it should splash cash

β€” June 19th 2025 at 11:57

Good to see government that values its academics (cough cough). Plus: New board criticized for lacking 'ops' people

Cybersecurity experts have started a formal review into the UK cybersecurity market, at the government's request, to identify future growth opportunities as it looks to grow the industry that's core to the country's Industrial Strategy.…

☐ β˜† βœ‡ The Register - Security

Sneaky Serpentine#Cloud slithers through Cloudflare tunnels to inject orgs with Python-based malware

β€” June 19th 2025 at 06:29

Phishing, Python and RATs, oh my

A sneaky malware campaign slithers through Cloudflare tunnel subdomains to execute in-memory malicious code and give unknown attackers long-term access to pwned machines.…

☐ β˜† βœ‡ The Register - Security

Iran’s internet goes offline for hours amid claims of β€˜enemy abuse’

β€” June 19th 2025 at 03:46

Bank and crypto outfits hit after Israeli commander mentioned attacks expanding to β€˜other areas’

The government of Iran appears to have shut down the internet within its borders, perhaps in response to Israel-linked cyberattacks.…

☐ β˜† βœ‡ The Register - Security

Minecraft cheaters never win ... but they may get malware

β€” June 18th 2025 at 21:06

Infostealers posing as popular cheat tools are cropping up on GitHub

Trojanized Minecraft cheat tools hosted on GitHub have secretly installed stealers that siphon credentials, crypto wallets, and other sensitive data when executed by players.…

☐ β˜† βœ‡ The Register - Security

Asana's cutting-edge AI feature ran into a little data leakage problem

β€” June 18th 2025 at 19:32

New MCP server was shut down for nearly two weeks

Asana has fixed a bug in its Model Context Protocol (MCP) server that could have allowed users to view other organizations' data, and the experimental feature is back up and running after nearly two weeks of downtime to fix the issue.…

☐ β˜† βœ‡ The Register - Security

Veeam patches third critical RCE bug in Backup & Replication in space of a year

β€” June 18th 2025 at 13:33

Version 13 can’t come soon enough

Veeam Backup & Replication users are urged to apply the latest patches that fix another critical bug leading to remote code execution (RCE) on backup servers.…

☐ β˜† βœ‡ The Register - Security

How to bridge the MFA gap

β€” June 18th 2025 at 08:00

If a credential is worth protecting, it's worth protecting well.

Sponsored feature What do flossing and multi-factor authentication (MFA) have in common? Each is highly beneficial, yet far too few people do them consistently. MFA helps protect organizations from credential-based attacks, but according to the Cyber Readiness Institute, only 35% of businesses globally bother with it.…

☐ β˜† βœ‡ The Register - Security

Amazon CISO: Iranian hacking crews β€˜on high alert’ since Israel attack

β€” June 18th 2025 at 07:29

Meanwhile, next-gen script kiddies are levelling up faster thanks to agentic AI

Interview Iran's state-sponsored cyber operatives and hacktivists have all increased their activities since the military conflict with Israel erupted last week – but not necessarily in the way that Amazon chief information security officer CJ Moses expected.…

☐ β˜† βœ‡ The Register - Security

Trump administration set to waive TikTok sell-or-die deadline for a third time

β€” June 18th 2025 at 03:33

Quick reminder: The law that banned the app is called β€˜Protecting Americans from Foreign Adversary Controlled Applications Act’

The Trump administration is set to again waive the 2024 law that requires the made-in-China social network TikTok to either sell its US operations to a local company or stop operating on US soil.…

☐ β˜† βœ‡ The Register - Security

AWS locks down cloud security, hits 100% MFA enforcement for root users

β€” June 17th 2025 at 21:15

Plus adds a ton more security capabilities for cloud customers at re:Inforce

Amazon Web Services hit a major multi-factor authentication milestone, achieving 100 percent MFA enforcement for root users across all types of AWS accounts.…

☐ β˜† βœ‡ The Register - Security

Sitecore CMS flaw let attackers brute-force 'b' for backdoor

β€” June 17th 2025 at 16:58

Hardcoded passwords and path traversals keeping bug hunters in work

Security researchers have issued a warning about a pre-authentication exploit chain affecting a CMS used by some of the biggest companies in the world.…

☐ β˜† βœ‡ The Register - Security

Redefining identity security in the age of agentic AI

β€” June 17th 2025 at 15:00

Now AI agents have identity, too. Here's how to handle it

Partner content The rise of agentic AI systems is rewriting the rules of cybersecurity. Unlike generative AI, which relies on predefined instructions or prompts, AI agents operate autonomously, learn continuously, and act with minimal oversight. They collaborate across systems and adapt to dynamic environments. As enterprises scale their AI deployments, identity security must evolve in lockstep to preserve control, mitigate risk, and enforce trust.…

☐ β˜† βœ‡ The Register - Security

23andMe hit with Β£2.3M fine after exposing genetic data of millions

β€” June 17th 2025 at 13:46

Penalty follows year-long probe into flaws that allowed attack to affect so many

The UK's data watchdog is fining beleaguered DNA testing outfit 23andMe Β£2.31 million ($3.13 million) over its 2023 mega breach.…

☐ β˜† βœ‡ The Register - Security

Scattered Spider has moved from retail to insurance

β€” June 16th 2025 at 21:58

Google threat analysts warn the team behind the Marks & Spencer break-in has moved on

Cyber-crime crew Scattered Spider has infected US insurance companies following a series of ransomware attacks against American and British retailers, according to Google, which urged this sector to be on "high alert."…

☐ β˜† βœ‡ The Register - Security

Remorseless extortionists claim to have stolen thousands of files from Freedman HealthCare

β€” June 16th 2025 at 18:47

The group has previously threatened to SWAT cancer patients and leaked pre-op plastic surgery photos

UPDATED An extortion gang claims to have breached Freedman HealthCare, a data and analytics firm whose customers include state agencies, health providers, and insurance companies, and is threatening to dump tens of thousands of sensitive files early Tuesday morning.…

☐ β˜† βœ‡ The Register - Security

Canada's WestJet says 'expect interruptions' online as it navigates cybersecurity turbulence

β€” June 16th 2025 at 16:15

Flights still flying - just don't count on the app or website working smoothly

updated Canadian airline WestJet is warning of "intermittent interruptions or errors" on its app and website as it investigates a cybersecurity incident.…

☐ β˜† βœ‡ The Register - Security

Eurocops arrest suspected Archetyp admin, shut down mega dark web drug shop

β€” June 16th 2025 at 14:28

Marketplace as big as Silk Road had more than 600k users and turnover of 'at least' €250M

Operation Deep Sentinel is the latest international law enforcement collaboration against cybercrime, shutting down Archetyp – one of the largest dark web drug marketplaces.…

❌