Menu

Gallery

‘Anomalous surge in DNS queries’ knocked Microsoft’s cloud off the web last week
Facebook says dump of 533m accounts is old news. But my date of birth, name, etc haven’t changed in years, Zuck
QNAP caught napping as disclosure delay expires, critical NAS bugs revealed
Criminals send out fake “census form” reminder – don’t fall for it!
S3 Ep26: Apple 0-day, crypto vulnerabilities and PHP backdoor [Podcast]
Dutch watchdog fines Booking.com €475k after it kept customer data thefts quiet for more than 3 weeks
Wi-Fi slinger Ubiquiti hints at source code leak after claim of ‘catastrophic’ cloud intrusion emerges
How Cybereason is reversing the adversary advantage
Pair accused of turning photos into vids to crack tax dept facial recognition system in China
Payment app MobiKwik denies customer data was stolen from it, has no idea how the info ended up on the dark web: Maybe it was your fault?
Browser tracking protections won’t stop tracking, warns DuckDuckGo
Mozilla VPN now nudges users to put shields up on dodgy networks, adds LAN access
And that’s yet another UK education body under attack from ransomware: Servers, email, phones yanked offline
Money can buy you insurance against network break-ins but investing in infosec hygiene wouldn’t go amiss, says new NCSC chief
The cloud attack you didn’t see coming
UK’s Home Office dangles £32m for application support on comms-snooping network
Intel accused of wiretapping because it uses analytics to track keystrokes, mouse movements on its website
After oil giant Shell hit by Clop ransomware gang, workers’ visas dumped online as part of extortion attempt
Sitting comfortably? Then it’s probably time to patch, as critical flaw uncovered in npm’s netmask package
UK terror law reviewer calls for expanded police powers to imprison people who refuse to hand over passwords
Scottish National Party members found among list of names signed up to rival Alba Party after website whoopsie
PHP repository moved to GitHub after malicious code inserted under creator Rasmus Lerdorf’s name
Patch alert for Apple fans: Cybercrooks have already been exploiting this flaw in iPhones, iPads, and watches
Blockchain may be the machinery of mischief, but it can’t help telling the truth
Which cyberthreat should you care about most? Here’s a clue … all of them
OpenSSL shuts down two high-severity bugs: Flaws enable cert shenanigans, denial-of-service attacks
Defence Industrial Strategy suggests the UK is ready to start taking its homegrown infosec industry seriously
The pandemic-driven rush to cloud is compromising security
Authorization is the next big technical challenge
Google’s OSS-Fuzz extends fuzzing to Java apps
150,000 security cameras allegedly breached in “too much fun” hack
Belgian cops crack down on encrypted phone network Sky ECC in 200 overnight raids as firm denies criminal ties
Brit cybercops issue tender to rip and replace their formerly flaw-ridden CyberAlarm tool
Missing colleagues in cybersecurity? That’s no surprise – the world is missing 3.5 million
India pauses blockchain-powered SMS spam-scrubber after it swallows people’s one-time login codes
Beware the IDEs of March: Microsoft’s latest monthly fixes land after frantic Exchange Server updates
US newspaper’s ‘Biden will hack Russia’ claim: A good way to reassure Putin you’ll leave him alone
European Banking Authority restores email service in wake of Microsoft Exchange hack
Serious Security: Webshells explained in the aftermath of HAFNIUM attacks
So it appears some of you really don’t want us to use the word ‘hacker’ when we really mean ‘criminal’
GitHub bug briefly gave valid authenticated session cookies to wrong users
Azure flings out free virtual trusted platform module for cloudy VMs
Apple emits patches for iOS, macOS, Safari, etc to stop dodgy websites hijacking people’s gadgets
Google engineer urges web devs to step up and secure their code in this data-spilling Spectre-haunted world
McAfee to offload enterprise business for $4bn, focus on consumer security
University of the Highlands and Islands shuts down campuses as it deals with ‘ongoing cyber incident’
SolarWinds just keeps getting worse: New strain of backdoor malware found in probe
Cybersecurity in 2021: Stopping the madness
6 security risks in software development and how to address them
The torture garden of Microsoft Exchange: Grant us the serenity to accept what they cannot EOL
US National Security Council urges review of Exchange Servers in wake of Hafnium attack
Intel CPU interconnects can be exploited by malware to leak encryption keys and other info, academic study finds
Poison packages – “Supply Chain Risks” user hits Python community with 4000 fake modules
EFF urges Google to ground its FLoC: ‘Pro-privacy’ third-party cookie replacement not actually great for privacy
Oh SITA: Airline IT provider confirms passenger data leaked after major ‘cyber-attack’
While Reg readers know the difference between a true hacker and cyber-crook, for everyone else, hacking means illegal activity
Dutch government: Did we say 10 ‘high data protection risks’ in Google Workspace block adoption? Make that 8
Biden administration labels China top tech threat, promises proportionate responses to cyberattacks
AdGuard names 6,000+ web trackers that use CNAME chicanery: Feel free to feed them into your browser’s filter
Like a challenge in a high profile ‘face-of-IT’ role? Welcome to the Home Office
Using TikTok? Check out these six security tips
Would you let users vouch for unknown software’s safety with an upvote? Google does
Another Chrome zero-day exploit – so get that update done!
How (NOT?!) to jailbreak your iPhone
Qualys hit with ransomware: Customer invoices leaked on extortionists’ Tor blog
Proof of concept code published for latest Saltstack CVE: Don’t be an update laggard
Cybersecurity threats aren’t getting any smaller. Could big data help?
I see you: your home-working photos reveal more than you think!
It’s not easy being green: EV HTTPS cert seller Sectigo questions Chrome’s logic in burying EV HTTPS cert info
Hacking is not a crime – and the media should stop using ‘hacker’ as a pejorative
TPG buys Thycotic, immediately merges it with Centrify to create ~$230m access management monster
Microsoft promises end-to-end encrypted Teams calls for some, invites you to go passwordless with Azure AD
Eugene Kaspersky says cyber-crooks coined it during COVID and will take a break to spend their loot
Microsoft fixes four zero-day flaws in Exchange Server exploited by China’s ‘Hafnium’ spies to steal victims’ data
Search crimes – how the Gootkit gang poisons Google searches
Gootkit malware crew using SEO to get pwned websites in front of unwitting marks
Perl.com theft blamed on social engineering attack: Registrar ‘convinced’ to alter DNS records by miscreants
Chinese businessman plotted with GE insider to steal transistor secrets, say Feds
Malware attack that crippled Mumbai’s power system came from China, claims infosec intel outfit Recorded Future
Cyber-attackers work 24/7 … but what about your security team?
Mobile spyware fan Saudi Crown Prince accused by US intel of Khashoggi death
Imperva pretty adamant that security analytics aggregator product Sonar is not ‘one dashboard to rule them all’
Google looks at bypass in Chromium’s ASLR security defense, throws hands up, won’t patch garbage issue
Half a million stolen French medical records, drowned in feeble excuses
India’s demand to identify people on chat apps will ‘break end-to-end encryption’, say digital rights warriors
1Password has none, KeePass has none… So why are there seven embedded trackers in the LastPass Android app?
UK’s National Cyber Security Centre sidles in to help firm behind hacked NurseryCam product secure itself
Ever felt that a few big tech companies are following you around the internet? That’s because … they are
Alexa, swap out this code that Amazon approved for malware… Installed Skills can double-cross their users
Revealed: The military radar system swiped from aerospace biz, leaked online by Clop ransomware gang
‘We’re finding bugs way faster than we can fix them’: Google sponsors 2 full-time devs to improve Linux security
Think you know all about security pen-testing in the cloud? Here’s how to prove it
Mozilla Firefox keeps cookies kosher with quarantine scheme, 86s third-party cookies in new browser build
What’s CNAME of your game? This DNS-based tracking defies your browser privacy defenses
Indian Railways suffers unspecified security ‘breaches in various IT applications’
Microsoft president asks Congress to force private-sector orgs to publicly admit when they’ve been hacked
VMware warns of critical remote code execution flaw in vSphere HTML5 client
They break into your network but do nothing themselves: ‘Initial access brokers’ resell stolen creds for $7k a pop
Clop ransomware gang leaks online what looks like stolen Bombardier blueprints of GlobalEye radar snoop jet
Keybase secure messaging fixes photo-leaking bug – patch now!