Menu

Gallery

Researchers claim Windows Defender can be fooled into deleting databases
China creates ‘Information Support Force’ to improve networked defence capabilities
MITRE admits ‘nation state’ attackers touched its NERVE R&D operation
Sacramento airport goes no-fly after AT&T internet cable snipped
WhatsApp, Threads, more banished from Apple App Store in China
Cybercriminals threaten to leak all 5 million records from stolen database of high-risk individuals
Germany cuffs alleged Russian spies over plot to bomb industrial and military targets
Ransomware feared as IT ‘issues’ force Octapharma Plasma to close 150+ centers
Crooks exploit OpenMetadata holes to mine crypto – and leave a sob story for victims
House passes bill banning Uncle Sam from snooping on citizens via data brokers
Korean researcher details scheme abusing Apple’s third-party pickup policy
185K people’s sensitive data in the pits after ransomware raid on Cherry Health
EU tells Meta it can’t paywall privacy
Prolific phishing-made-easy emporium LabHost knocked offline in cyber-cop op
Java services hit hardest by third-party vulnerabilities, report says
Cisco creates architecture to improve security and sell you new switches
Singapore infosec boss warns China/West tech split will be bad for interoperability
Taiwanese film studio snaps up Chinese surveillance camera specialist Dahua
Hugely expanded Section 702 surveillance powers set for US Senate vote
Kremlin’s Sandworm blamed for cyberattacks on US, European water utilities
Exploit code for Palo Alto Networks zero-day now public
OpenAI’s GPT-4 can exploit real vulnerabilities by reading security advisories
Japanese government rejects Yahoo! infosec improvement plan
Fire in the Cisco! Networking giant’s Duo MFA message logs stolen in phish attack
Most developers have adopted devops, survey says
MGM says FTC can’t possibly probe its ransomware downfall – watchdog chief Lina Khan was a guest at the time
Alleged cryptojacker accused of stealing $3.5M from cloud to mine under $1M in crypto
SIM swap crooks solicit T-Mobile US, Verizon staff via text to do their dirty work
Open sourcerers say suspected xz-style attacks continue to target maintainers
Change Healthcare’s ransomware attack costs edge toward $1B so far
Google location tracking deal could be derailed by politics
Better application networking and security with CAKES
CISA in a flap as Chirp smart door locks can be trivially unlocked remotely
Roku makes 2FA mandatory for all after nearly 600K accounts pwned
Delinea Secret Server customers should apply latest patches
US senator wants to put the brakes on Chinese EVs
Identifying third-party risk
US House approves FISA renewal – warrantless surveillance and all
Zero-day exploited right now in Palo Alto Networks’ GlobalProtect gateways
Rust gets security fix for Windows vulnerability
Google One VPN axed for everyone but Pixel loyalists … for now
Microsoft breach allowed Russian spies to steal emails from US government
French issue alerte rouge after local governments knocked offline by cyber attack
Apple stops warning of ‘state-sponsored’ attacks, now alerts about ‘mercenary spyware’
Space Force boss warns ‘the US will lose’ without help from Musk and Bezos
96% of US hospital websites share visitor info with Meta, Google, data brokers
Global taxi software vendor exposes details of nearly 300K across UK and Ireland
It’s 2024 and Intel silicon is still haunted by data-spilling Spectre
Rust rustles up fix for 10/10 critical command injection bug on Windows
X fixes URL blunder that could enable convincing social media phishing campaigns
Turning the tide on third-party risk
Chrome Enterprise Premium promises extra security – for a fee
Synopsys takes aim at software supply chain risks
Microsoft squashes SmartScreen security bypass bug exploited in the wild
Got an unpatched LG ‘smart’ television? It could be watching you back
UK businesses shockingly unaware of how to handle security threats
Parasoft unveils safety testing tool for C and C++ apps
US insurers use drone photos to deny home insurance policies
Home Depot confirms workers’ data snatched after miscreant dumps it online
Puppies, kittens, data at risk after ‘cyber incident’ at veterinary giant
Change Healthcare faces second ransomware dilemma weeks after ALPHV attack
Head of Israeli cyber spy unit exposed … by his own privacy mistake
What can be done to protect open source devs from next xz backdoor drama?
Eclipse joins with industry groups to secure open source
US government excoriates Microsoft for ‘avoidable errors’ but keeps paying for its products
Hotel check-in terminal bug spews out access codes for guest rooms
Academics probe Apple’s privacy settings and get lost and confused
World’s second-largest eyeglass lens-maker blinded by infosec incident
Feds probe massive alleged classified US govt data theft and leak
Ivanti commits to secure-by-design overhaul after vulnerability nightmare
Ransomware gang did steal residents’ confidential data, UK city council admits
When AI attacks
Nearly 1M medical records feared stolen from City of Hope cancer centers
Cyberattack hits Omni Hotels systems, taking out bookings, payments, door locks
Security pioneer Ross Anderson dies at 67
Google bakes new cookie strategy that will leave crooks with a bad taste
Rust memory safety explained
Meet clickjacking’s slicker cousin, ‘gesture jacking,’ aka ‘cross window forgery’
Microsoft slammed for lax security that led to China’s cyber-raid on Exchange Online
Feds finally decide to do something about years-old SS7 spy holes in phone networks
OWASP server blunder exposes decade of resumes
Pandabuy admits to data breach of 1.3 million unique records
Microsoft warns deepfake election subversion is disturbingly easy
Rubrik files to go public following alliance with Microsoft
Polish officials may face criminal charges in Pegasus spyware probe
INC Ransom claims to be behind ‘cyber incident’ at UK city council
Happy 20th birthday Gmail, you’re mostly grown up – now fix the spam
Avoiding the dangers of AI-generated code
Apple’s GoFetch silicon security fail was down to an obsession with speed
Six banks share customer info to help Singapore fight money laundering
US House of Reps tells staff: No Microsoft Copilot for you!
Malicious xz backdoor reveals fragility of open source
Nearly 3M people hit in Harvard Pilgrim healthcare data theft
Ex-White House CIO tells The Reg: TikTok ban may be diplomatic disaster
AT&T admits massive 70M+ mid-March customer data dump is real though old
Rust developers at Google are twice as productive as C++ teams
Malicious SSH backdoor sneaks into xz, Linux world’s data compression library
Easy-to-use make-me-root exploit lands for recent Linux kernels. Get patching
JetBrains keeps mum on 26 ‘security problems’ fixed after Rapid7 spat
FTX crypto-crook Sam Bankman-Fried gets 25 years in prison