All the latest Tech/Sec news in one place!

Refresh Feeds
All Categories 237 Technology 82 Science 60 Security 50 Programming 20 Engineering 25
Mixed View Grouped by Category

Crims hit a $20M jackpot via malware-stuffed ATMs

The registerSecurity4 hours ago
FBI warns these cyber-physical attacks are on the rise Thieves stole more than $20 million from compromised ATMs last year using a malware-assisted technique that the FBI says is on the uptick across the United States.…

Adidas investigates third-party data breach after criminals claim they pwned the sportswear giant

The registerSecurity23 hours ago
'Potential data protection incident' at an 'independent licensing partner,' we're told Adidas has confirmed it is investigating a third-party breach at one of its partner companies after digital thieves claimed they stole information and technical data from the German sportswear giant.…

ShinyHunters claims it drove off with 1.7M CarGurus records

The registerSecurity1 days ago
Latest in a rash of grab-and-leak data incidents CarGurus purportedly suffered a data breach with 1.7 million corporate records stolen, according to a notorious cybercrime crew that posted the online vehicle marketplace on its leak site on Wednesday.…

Fraudster hacked hotel system, paid 1 cent for luxury rooms, Spanish cops say

The registerSecurity1 days ago
'First time we have detected a crime using this method,' cops say Spanish police arrested a hacker who allegedly manipulated a hotel booking website, allowing him to pay one cent for luxury hotel stays. He also raided the mini-bars and didn't settle some of those tabs, police say.…

Deutsche Bahn back on track after DDoS yanks the brakes

The registerSecurity1 days ago
National rail bookings and timetables disrupted for nearly 24 hours If you wanted to book a train trip in Germany recently, you would have been out of luck. The country's national rail company says that its services were disrupted for hours because of a cyberattack.…

China-linked snoops have been exploiting Dell 0-day since mid-2024, using 'ghost NICs' to avoid detection

The registerSecurity1 days ago
Full scale of infections remains 'unknown' China-linked attackers exploited a maximum-severity hardcoded-credential bug in Dell RecoverPoint for Virtual Machines as a zero-day since at least mid-2024. It's all part of a long-running effort to backdoor infected machines for long-term access, accordin...

China remains embedded in US energy networks 'for the purpose of taking it down'

The registerSecurity2 days ago
Plus 3 new goon squads targeted critical infrastructure last year Three new threat groups began targeting critical infrastructure last year, while a well-known Beijing-backed crew - Volt Typhoon - continued to compromise cellular gateways and routers, and then break into US electric, oil, and gas co...

Polish cops nab 47-year-old man in Phobos ransomware raid

The registerSecurity2 days ago
Police say seized kit contained logins, passwords, and server IP addresses Polish police have arrested and charged a man over ties to the Phobos ransomware group following a property raid.…

Canada Goose ruffles feathers over 600K record dump, says leak is old news

The registerSecurity3 days ago
Fashion brand latest to succumb to ShinyHunters' tricks Canada Goose says an advertised breach of 600,000 records is an old raid and there are no signs of a recent compromise.…

Google patches Chrome zero-day as in-the-wild exploits surface

The registerSecurity3 days ago
High-severity CSS flaw let malicious webpages run code inside the sandbox Google has quietly pushed out an emergency Chrome fix after attackers were caught exploiting the browser's first reported zero-day of 2026.…

Infosec exec sold eight zero-day exploit kits to Russia, says DoJ

The registerSecurity3 days ago
PLUS: Fake ransomware group exposed; EC blesses Google's big Wiz deal; Alleged sewage hacker cuffed; And more Infosec in Brief  The former General Manager of defense contractor L3Harris’s cyber subsidiary Trenchant sold eight zero-day exploit kits to Russia, according to a court filing last week....

Top Dutch telco Odido admits 6.2M customers caught in contact system caper

The registerSecurity6 days ago
Names, addresses, bank account numbers accessed – but biz insists passwords and call data untouched The Netherlands' largest mobile network operator (MNO) has admitted that a breach of its customer contact system may have affected around 6.2 million people.…

Who's the bossware? Ransomware slingers like employee monitoring tools, too

The registerSecurityFeb 12, 2026
As if snooping on your workers wasn't bad enough Your supervisor may like using employee monitoring apps to keep tabs on you, but crims like the snooping software even more. Threat actors are now using legit bossware to blend into corporate networks and attempt ransomware deployment.…

Apple patches decade-old iOS zero-day, possibly exploited by commercial spyware

The registerSecurityFeb 12, 2026
Flaw abused 'in an extremely sophisticated attack against specific targeted individuals' Apple patched a zero-day vulnerability affecting every iOS version since 1.0, used in what the company calls an "extremely sophisticated attack" against targeted individuals.…

Supply chain attacks now fuel a 'self-reinforcing' cybercrime economy

The registerSecurityFeb 12, 2026
Researchers say breaches link identity abuse, SaaS compromise, and ransomware into a cascading cycle Cybercriminals are turning supply chain attacks into an industrial-scale operation, linking breaches, credential theft, and ransomware into a "self-reinforcing" ecosystem, researchers say.…

Google: China's APT31 used Gemini to plan cyberattacks against US orgs

The registerSecurityFeb 12, 2026
Meanwhile, IP-stealing 'distillation attacks' on the rise A Chinese government hacking group that has been sanctioned for targeting America's critical infrastructure used Google's AI chatbot, Gemini, to auto-analyze vulnerabilities and plan cyberattacks against US organizations, the company says.…

Payroll pirates are conning help desks to steal workers' identities and redirect paychecks

The registerSecurityFeb 11, 2026
Attackers using social engineering to exploit business processes, rather than tunnelling in via tech Exclusive  When fraudsters go after people's paychecks, "every employee on earth becomes a target," according to Binary Defense security sleuth John Dwyer.…

Singapore spent 11 months booting China-linked snoops out of telco networks

The registerSecurityFeb 10, 2026
Operation Cyber Guardian involved 100-plus staff across government and industry Singapore spent almost a year flushing a suspected China-linked espionage crew out of its telecom networks in what officials describe as the country's largest cyber defense operation to date.…

Nearly 17,000 Volvo staff dinged in supplier breach

The registerSecurityFeb 10, 2026
HR outsourcer Conduent confirms intruders accessed benefits-related records tied to US personnel Nearly 17,000 Volvo employees had their personal data exposed after cybercriminals breached Conduent, an outsourcing giant that handles workforce benefits and back-office services.…

Someone's attacking SolarWinds WHD to steal high‑privilege credentials - but we don't know who or how

The registerSecurityFeb 9, 2026
So many CVEs, so little time Digital intruders exploited buggy SolarWinds Web Help Desk (WHD) instances in December to break into victims' IT environments, move laterally, and steal high-privilege credentials, according to Microsoft researchers.…

Dutch data watchdog snitches on itself after getting caught in Ivanti zero-day attacks

The registerSecurityFeb 9, 2026
Staff data belonging to the regulator and judiciary's governing body accessed The Dutch Data Protection Authority (AP) says it was one of the many organizations popped when attackers raced to exploit recent Ivanti vulnerabilities as zero-days.…

European Commission probes intrusion into staff mobile management backend

The registerSecurityFeb 9, 2026
Officials explore issue affecting infrastructure after CERT-EU detected suspicious activity Brussels is digging into a cyber break-in that targeted the European Commission's mobile device management systems, potentially giving intruders a peek inside the official phones carried by EU staff.…

Flickr emails users about data breach, pins it on third party

The registerSecurityFeb 6, 2026
Attackers may have snapped user locations and activity information, message warns Legacy image-sharing website Flickr suffered a data breach, according to customer emails seen by The Register.…

Substack says intruder lifted emails, phone numbers in months-old breach

The registerSecurityFeb 5, 2026
Contact details were accessed in an intrusion that went undetected for months, the blogging outfit says Newsletter platform Substack has admitted that an intruder swiped user contact details months before the company noticed, forcing it to warn writers and readers that their email addresses and othe...

Asia-based government spies quietly broke into critical networks across 37 countries

The registerSecurityFeb 5, 2026
And their toolkit includes a new, Linux kernel rootkit A state-aligned cyber group in Asia compromised government and critical infrastructure organizations across 37 countries in an ongoing espionage campaign, according to security researchers.…

Betterment breach may expose 1.4M users after social engineering attack

The registerSecurityFeb 5, 2026
Breach-tracking site flags dataset following impersonation-based intrusion Breach-tracking site Have I Been Pwned (HIBP) claims a cyberattack on Betterment affected roughly 1.4 million users – although the investment company has yet to publicly confirm how many customers were affected by January's...

Italy claims cyberattacks 'of Russian origin' are pelting Winter Olympics

The registerSecurityFeb 5, 2026
Right on cue, petulant hacktivists attempt to disrupt yet another global sporting event Italy's foreign minister says the country has already started swatting away cyberattacks from Russia targeting the Milano Cortina Winter Olympics.…

AWS intruder achieved admin access in under 10 minutes thanks to AI assist, researchers say

The registerSecurityFeb 4, 2026
LLMs automated most phases of the attack UPDATED  A digital intruder broke into an AWS cloud environment and in just under 10 minutes went from initial access to administrative privileges, thanks to an AI speed assist.…

Nitrogen ransomware is so broken even the crooks can't unlock your files

The registerSecurityFeb 4, 2026
Gang walks away with nothing, victims are left with irreparable hypervisors Cybersecurity experts usually advise victims against paying ransomware crooks, but that advice goes double for those who have been targeted by the Nitrogen group. There's no way to get your data back from them!…

CISA updated ransomware intel on 59 bugs last year without telling defenders

The registerSecurityFeb 3, 2026
GreyNoise's Glenn Thorpe counts the cost of missed opportunities On 59 occasions throughout 2025, the US Cybersecurity and Infrastructure Security Agency (CISA) silently tweaked vulnerability notices to reflect their use by ransomware crooks. Experts say that's a problem.…

Polish cops bail 20-year-old bedroom botnet operator

The registerSecurityFeb 3, 2026
DDoSer of 'strategically important' websites admitted to most charges Polish authorities have cuffed a 20-year-old man on suspicion of carrying out DDoS attacks.…

Notepad++ hijacking blamed on Chinese Lotus Blossom crew behind Chrysalis backdoor

The registerSecurityFeb 2, 2026
The group targets telecoms, critical infrastructure - all the usual high-value orgs Security researchers have attributed the Notepad++ update hijacking to a Chinese government-linked espionage crew called Lotus Blossom (aka Lotus Panda, Billbug), which abused weaknesses in the update infrastructure ...

Russia-linked APT28 attackers already abusing new Microsoft Office zero-day

The registerSecurityFeb 2, 2026
Ukraine’s CERT says the bug went from disclosure to active exploitation in days Russia-linked attackers are already exploiting Microsoft's latest Office zero-day, with Ukraine's national cyber defense team warning that the same bug is being used to target government agencies inside the country and...

Notepad++ update service hijacked in targeted state-linked attack

The registerSecurityFeb 2, 2026
Breach lingered for months before stronger signature checks shut the door A state-sponsored cyber criminal compromised Notepad++'s update service in 2025, according to the project's author.…

Infrastructure cyberattacks are suddenly in fashion. We can buck the trend

The registerSecurityFeb 2, 2026
Don't be scared of the digital dark – learn how to keep the lights on Opinion  Barely a month into 2026, electrical power infrastructure on two continents has tested positive for cyberattacks. One fell flat as attempts to infiltrate and disrupt the Polish distribution grid were rebuffed and repor...

Thousands more Oregon residents learn their health data was stolen in TriZetto breach

The registerSecurityJan 30, 2026
Parent company Cognizant hit with multiple lawsuits Thousands more Oregonians will soon receive data breach letters in the continued fallout from the TriZetto data breach, in which someone hacked the insurance verification provider and gained access to its healthcare provider customers across multip...

To stop crims, Google starts dismantling residential proxy network they use to hide

The registerSecurityJan 29, 2026
The Chocolate Factory strikes again, targeting the infrastructure attackers use to stay anonymous Crims love to make it look like their traffic is actually coming from legit homes and businesses, and they do so by using residential proxy networks. Now, Google says it has "significantly degraded" wha...

ShinyHunters swipes right on 10M records in alleged dating app data grab

The registerSecurityJan 29, 2026
Extortion crew says it's found love in someone else's info as Match Group plays down the impact ShinyHunters has added a fresh notch to its breach belt, claiming it has pinched more than 10 million records from Match Group, a US firm that owns some of the world's most widely used swipe-based dating ...

Cyberattack on Poland's power grid could have turned deadly in winter cold

The registerSecurityJan 29, 2026
Close call after an apparently deliberate attempt to starve a country of energy at the worst time Cybersecurity experts involved in the cleanup of the cyberattacks on Poland's power network say the consequences could have been lethal.…

Ransomware crims forced to take off-RAMP as FBI seizes forum

The registerSecurityJan 28, 2026
Cybercrime solved. The end Ransomware crims have just lost one of their best business platforms. US law enforcement has seized the notorious RAMP cybercrime forum's dark web and clearnet domains.…

Everybody is WinRAR phishing, dropping RATs as fast as lightning

The registerSecurityJan 28, 2026
Russians, Chinese spies, run-of-the-mill crims … Come one, come all. Everyone from Russian and Chinese government goons to financially motivated miscreants is exploiting a long-since-patched WinRAR vuln to bring you infostealers and Remote Access Trojans (RATs).…

Let them eat sourdough: ShinyHunters claims Panera Bread as stolen credentials victim

The registerSecurityJan 27, 2026
Plus, the gang says it got in via Microsoft Entra SSO ShinyHunters says it stole several slices of data from Panera Bread, but that's just the yeast of everyone's problems. The extortionist gang also claims to have stolen data from CarMax and Edmunds, in addition to three other organizations it post...

China-linked group accused of spying on phones of UK prime ministers' aides – for years

The registerSecurityJan 27, 2026
Reports say Salt Typhoon attackers accessed handsets of senior govt folk Chinese state-linked hackers are accused of spending years inside the phones of senior Downing Street officials, exposing private communications at the heart of the UK government.…

Canva among ~100 targets of ShinyHunters Okta identity-theft campaign

The registerSecurityJan 26, 2026
Atlassian, RingCentral, ZoomInfo also among tech targets ShinyHunters has targeted around 100 organizations in its latest Okta single sign-on (SSO) credential stealing campaign, according to researchers and the criminal group itself.…

Data thieves borrow Nike's 'Just Do It' mantra, claim they ran off with 1.4TB

The registerSecurityJan 26, 2026
US sports brand launches probe after extortion crew WorldLeaks claims it stole huge dataset Nike says it is probing a possible breach after extortion crew WorldLeaks claimed to have lifted 1.4TB of internal data from the sportswear giant and posted samples on its leak site.…

Moscow likely behind wiper attack on Poland’s power grid, experts say

The registerSecurityJan 26, 2026
Cyber sleuths believe Sandworm up to its old tricks with a brand-new sabotage toy Russia was probably behind the failed attempts to compromise the systems of Poland's power companies in December, cybersecurity researchers claim.…

ShinyHunters claims Okta customer breaches, leaks data belonging to 3 orgs

The registerSecurityJan 23, 2026
'A lot more' victims to come, we're told ShinyHunters has claimed responsibility for an Okta voice-phishing campaign during which the extortionist crew allegedly gained access to Crunchbase and Betterment.…

London boroughs limping back online months after cyberattack

The registerSecurityJan 23, 2026
Direct debits? Maybe February. Birth certificates? Dream on. Council tax bills? Oh, those are coming Hammersmith & Fulham Council says payments are now being processed as usual, two months after a cyberattack that affected multiple boroughs in the UK's capital city.…

Crims hit the easy button for Scattered-Spider style helpdesk scams

The registerSecurityJan 22, 2026
Teach a crook to phish… Criminals can more easily pull off social engineering scams and other forms of identity fraud thanks to custom voice-phishing kits being sold on dark web forums and messaging platforms.…

Crims compromised energy firms' Microsoft accounts, sent 600 phishing emails

The registerSecurityJan 22, 2026
Logging in, not breaking in Unknown attackers are abusing Microsoft SharePoint file-sharing services to target multiple energy-sector organizations, harvest user credentials, take over corporate inboxes, and then send hundreds of phishing emails from compromised accounts to contacts inside and outsi...