All the latest Tech/Sec news in one place!

Refresh Feeds
All Categories 253 Technology 98 Science 60 Security 50 Programming 20 Engineering 25
Mixed View Grouped by Category

FCC looks to torch Biden-era cyber rules sparked by Salt Typhoon mess

The registerSecurity11 hours ago
Regulator sides with telcos that claimed new cybersecurity duties were too ‘burdensome’ The Federal Communications Commission (FCC) will vote this week on whether to scrap Biden-era cybersecurity rules, enacted after the Salt Typhoon attacks came to light in 2024, that required telecom carriers ...

Google Chrome bug exploited as an 0-day - patch now or risk full system compromise

The registerSecurity11 hours ago
Seventh Chrome 0-day this year Google pushed an emergency patch on Monday for a high-severity Chrome bug that attackers have already found and exploited in the wild.…

'Largest-ever' cloud DDoS attack pummels Azure with 3.64B packets per second

The registerSecurity1 days ago
Aisuru botnet strikes again, bigger and badder Azure was hit by the "largest-ever" cloud-based distributed denial of service (DDoS) attack, originating from the Aisuru botnet and measuring 15.72 terabits per second (Tbps), according to Microsoft.…

Security researcher calls BS on Coinbase breach disclosure timeline

The registerSecurity1 days ago
Claims he reported the attack in January after fraudsters tried to scam him A security researcher says Coinbase knew about a December 2024 security breach during which miscreants bribed its support staff into handing over almost 70,000 customers' details at least four months before it disclosed the ...

Game over: Europol storms gaming platforms in extremist content sweep

The registerSecurity1 days ago
Law enforcement agency’s referral blitz hit gaming platforms hard, surfacing thousands of extremist URLs Europol's Internet Referral Unit (EU IRU) says a November 13 operation across gaming and "gaming-adjacent" services led its partners to report thousands of URLs hosting terrorist and hate-fuele...

Eurofiber admits crooks swiped data from French unit after cyberattack

The registerSecurity1 days ago
Regulator reports suggest telco was extorted, but company remains coy as to whether it paid French telco Eurofiber says cybercriminals swiped company data during an attack last week that also affected some internal systems.…

UK prosecutors seize £4.11M in crypto from Twitter mega-hack culprit

The registerSecurity1 days ago
Civil recovery order targets PlugwalkJoe's illicit gains while he serves US sentence British prosecutors have secured a civil recovery order to seize crypto assets worth £4.11 million ($5.39 million) from Twitter hacker Joseph James O'Connor, clawing back the proceeds of a scam that used hijacked c...

Crims poison 150K+ npm packages with token-farming malware

The registerSecurity4 days ago
Amazon spilled the TEA Yet another supply chain attack has hit the npm registry in what Amazon describes as "one of the largest package flooding incidents in open source registry history" - but with a twist. Instead of injecting credential-stealing code or ransomware into the packages, this one is a...

FBI flags scam targeting Chinese speakers with bogus surgery bills

The registerSecurity4 days ago
Crooks spoof US insurers, threaten bogus extradition to pry loose personal data and cash Chinese speakers in the US are being targeted as part of an aggressive health insurance scam campaign, the FBI warns.…

CISA flags imminent threat as Akira ransomware starts hitting Nutanix AHV

The registerSecurity4 days ago
Advisory updated as leading cybercrime crew opens up its target pool The US Cybersecurity and Infrastructure Security Agency (CISA) has issued new guidance to organizations on the Akira ransomware operation, which poses an imminent threat to critical sectors.…

Ransomed CTO falls on sword, refuses to pay extortion demand

The registerSecurity5 days ago
Checkout.com will instead donate the amount to fund cybercrime research Digitial extortion is a huge business, because affected orgs keep forking over money to get their data back. However, instead of paying a ransom demand after getting hit by extortionists last week, payment services provider Chec...

Extra, extra, read all about it: Washington Post clobbered in Clop caper

The registerSecurity5 days ago
Nearly 10,000 staff and contractors warned after attackers raided newspaper's Oracle EBS setup The Washington Post has confirmed that nearly 10,000 employees and contractors had sensitive personal data stolen in the Clop-linked Oracle E-Business Suite (EBS) attacks.…

Rhadamanthys malware admin rattled as cops seize a thousand-plus servers

The registerSecurity5 days ago
Operation Endgame also takes down Elysium and VenomRAT infrastructure International cops have pulled apart the Rhadamanthys infostealer operation, seizing 1,025 servers tied to the malware in coordinated raids between November 10-13.…

NHS supplier ends probe into ransomware attack that contributed to patient death

The registerSecurity5 days ago
Synnovis's 18-month forensic review of Qilin intrusion completed, now affected patients to be notified Synnovis has finally wrapped up its investigation into the 2024 ransomware attack that crippled pathology services across London, ending an 18-month effort to untangle what the NHS supplier describ...

Google sues 25 China-based scammers behind Lighthouse 'phishing for dummies' kit

The registerSecurity6 days ago
600+ phishing websites and 116 of these use a Google logo Google has filed a lawsuit against 25 unnamed China-based scammers, which it claims have stolen more than 115 million credit card numbers in the US as part of the Lighthouse phishing operation.…

UK's Cyber Security and Resilience Bill makes Parliamentary debut

The registerSecurity6 days ago
Various touch-ups added as MPs seek greater resilience to attacks on critical sectors UK government introduced the Cyber Security and Resilience (CSR) Bill to Parliament today, marking a significant overhaul of local cybersecurity legislation to sharpen the security posture of the most critical sect...

China hates crypto and scams, but is now outraged USA acquired bitcoin from a scammer

The registerSecurityNov 12, 2025
A new theory from the agency that brought us ‘America hacked itself to blame Beijing’ China’s National Computer Virus Emergency Response Center (CVERC) has alleged a nation-state entity, probably the USA, was behind a 2020 attack on a bitcoin mining operation and by doing so has gone into bat ...

Australia’s spy boss says authoritarian nations ready to commit ‘high-impact sabotage’

The registerSecurityNov 12, 2025

North Korean spies turn Google's Find Hub into remote-wipe weapon

The registerSecurityNov 11, 2025
KONNI espionage crew covertly abused Google’s Find My Device feature to remotely factory-reset Android phones North Korean state-backed spies have found a new way to torch evidence of their own cyber-spying – by hijacking Google's Find Hub service to remotely wipe Android phones belonging to the...

Hitachi-owned GlobalLogic admits data stolen on 10k current and former staff

The registerSecurityNov 11, 2025
Clop's Oracle EBS exploit spree shows no sign of slowing, claims nearly 30 more casualties in media, finance, and tech. Digital engineering outfit GlobalLogic says personal data from more than 10,000 current and former employees was exposed in the wave of Oracle E-Business Suite (EBS) attacks attrib...

Cyber insurers paid out over twice as much for UK ransomware attacks last year

The registerSecurityNov 11, 2025
Massive increase in policy claims… and data doesn’t even cover the major attacks of 2025 The number of successful cyber insurance claims made by UK organizations shot up last year, according to the latest figures from the industry's trade association.…

Russian broker pleads guilty to profiting from Yanluowang ransomware attacks

The registerSecurityNov 10, 2025
Aleksei Volkov faces years in prison, may have been working with other crews A Russian national will likely face several years in US prison after pleading guilty to a range of offenses related to his work with ransomware crews.…

Allianz UK joins growing list of Clop’s Oracle E-Business Suite victims

The registerSecurityNov 10, 2025
Insurance giant’s UK arm says cybercriminals misattributed the real victim Allianz UK confirms it was one of the many companies that fell victim to the Clop gang's Oracle E-Business Suite (EBS) attack after crims reported that they had attacked a subsidiary.…

Cybercrims plant destructive time bomb malware in industrial .NET extensions

The registerSecurityNov 7, 2025
Multi-year wait for destruction comes to an end for mystery attackers Security experts have helped remove malicious NuGet packages planted in 2023 that were designed to destroy systems years in advance, with some payloads not due to hit until the latter part of this decade.…

Bank of England says JLR's cyberattack contributed to UK's unexpectedly slower GDP growth

The registerSecurityNov 7, 2025
This kind of material economic impact from online crooks thought to be a UK-first The Bank of England (BoE) has cited the cyberattack on Jaguar Land Rover (JLR) as one of the reasons for the country's slower-than-expected GDP growth in its latest rates decision.…

Gootloader malware back for the attack, serves up ransomware

The registerSecurityNov 6, 2025
Move fast - miscreants compromised a domain controller in 17 hours Gootloader JavaScript malware, commonly used to deliver ransomware, is back in action after a period of reduced activity.…

SonicWall fingers state-backed cyber crew for September firewall breach

The registerSecurityNov 6, 2025
Spies, not crooks, were behind digital heist – damage stopped at the backups, says US cybersec biz SonicWall has blamed an unnamed, state-sponsored collective for the September break-in that saw cybercriminals rifle through a cache of firewall configuration backups.…

Malware-pwned laptop gifts cybercriminals Nikkei's Slack

The registerSecurityNov 6, 2025
Stolen creds let miscreants waltz into 17K employees' chats, spilling info on staff and partners Japanese media behemoth Nikkei has admitted to a data breach after miscreants slipped into its internal Slack workspace, exposing the personal details of more than 17,000 employees and business partners....

Attackers abuse Gemini AI to develop ‘Thinking Robot’ malware and data processing agent for spying purposes

The registerSecurityNov 5, 2025
Meanwhile, others tried to social-engineer the chatbot itself Nation-state goons and cybercrime rings are experimenting with Gemini to develop a "Thinking Robot" malware module that can rewrite its own code to avoid detection, and build an AI agent that tracks enemies' behavior, according to Google ...

M&S pegs cyberattack cleanup costs at £136M as profits slump

The registerSecurityNov 5, 2025
Retailer's tech systems aren’t down anymore, but the same can’t be said for its rocky financials Marks & Spencer says its April cyberattack will cost around £136 million ($177.2 million) in total.…

Russian spies pack custom malware into hidden VMs on Windows machines

The registerSecurityNov 4, 2025
Curly COMrades strike again Russia's Curly COMrades is abusing Microsoft's Hyper-V hypervisor in compromised Windows machines to create a hidden Alpine Linux-based virtual machine that bypasses endpoint security tools, giving the spies long-term network access to snoop and deploy malware.…

Cybercrooks getting violent more often to secure big payouts in Europe

The registerSecurityNov 4, 2025
France-based victims hit especially hard, while UK named most-targeted country generally Researchers are seeing a "dramatic" increase in cybercrime involving physical violence across Europe, with at least 18 cases reported since the start of the year.…

AN0M, the backdoored ‘secure’ messaging app for criminals, is still producing arrests after four years

The registerSecurityNov 4, 2025
55 cuffed last week after court ruled sting operation was legal Australian police last week made 55 arrests using evidence gathered with a backdoored messaging app that authorities distributed in the criminal community.…

Ransomware negotiator, pay thyself!

The registerSecurityNov 3, 2025
Rogues committed extortion while working for infosec firms A ransomware negotiator and an incident response manager at two separate cybersecurity firms have been indicted for allegedly carrying out ransomware attacks of their own against multiple US companies.…

Cybercrooks team up with organized crime to steal pricey cargo

The registerSecurityNov 3, 2025
Old-school cargo heists reborn in the cyber age Cybercriminals are increasingly orchestrating lucrative cargo thefts alongside organized crime groups (OCGs) in a modern-day resurgence of attacks on freight companies.…

Attackers targeting unpatched Cisco kit notice malware implant removal, install it again

The registerSecurityNov 2, 2025
PLUS: Cyber-exec admits selling secrets to Russia; LastPass isn't checking to see if you're dead; Nation-state backed Windows malware; and more Infosec in brief  Australia’s Signals Directorate (ASD) last Friday warned that attackers are installing an implant named “BADCANDY” on unpatched Cis...

Russia finally bites the cybercrooks it raised, arresting suspected Meduza infostealer devs

The registerSecurityOct 31, 2025
Rare case of the state turning on its own, but researchers say it may be doing so more often Russia's Interior Ministry says police have arrested three suspects it believes helped build and spread the Meduza infostealer.…

Attackers dig up $11M in Garden Finance crypto exploit

The registerSecurityOct 31, 2025
Bitcoin bridge biz offers 10 percent reward to attackers if they play nice Blockchain company Garden admits it was compromised and temporarily shut down its app after approximately $11 million worth of assets were stolen.…

Suspected Chinese snoops weaponize unpatched Windows flaw to spy on European diplomats

The registerSecurityOct 30, 2025
Expired security cert, real Brussels agenda, plus PlugX malware finish the job Cyber spies linked to the Chinese government exploited a Windows shortcut vulnerability disclosed in March – but that Microsoft hasn't fixed yet – to target European diplomats in an effort to steal defense and nationa...

Cyberpunks mess with Canada's water, energy, and farm systems

The registerSecurityOct 30, 2025
Infosec agency warns hacktivists broke into critical infrastructure systems to tamper with controls Hacktivists have breached Canadian critical infrastructure systems to meddle with controls that could have led to dangerous conditions, marking the latest in a string of real-world intrusions driven b...

Marketing giant Dentsu warns staff after Merkle data raid

The registerSecurityOct 29, 2025
Emails confirm payroll and bank details lifted in cyberattack on US subsidiary Global marketing giant Dentsu is writing to current and former staff after a cyberattack on a subsidiary led to bank, payroll, and other sensitive data being stolen.…

Australian police building AI to translate emoji used by ‘crimefluencers’

The registerSecurityOct 29, 2025
Five Eyes intel alliance has created a team to target these scum who prey on kids Australia’s Federal Police (AFP) is working on an AI to interpret emojis and the slang used online by Generation Z and Generation Alpha, so it can understand them when they discuss crime online.…

Marks & Spencer swaps out TCS for fresh helpdesk deal

The registerSecurityOct 28, 2025
Move follows months-long procurement process as retailer refreshes parts of its IT support setup UK retailer Marks & Spencer has replaced Tata Consultancy Services as its IT service desk provider following a procurement process that began in January.…

WSUS attacks hit 'multiple' orgs as Google and other infosec sleuths ring Redmond’s alarm bell

The registerSecurityOct 27, 2025
If at first you don’t succeed, patch and patch again More threat intel teams are sounding the alarm about a critical Windows Server Update Services (WSUS) remote code execution vulnerability, tracked as CVE-2025-59287 and now under active exploitation, just days after Microsoft pushed an emergency...

Iran's school for cyberspies could've used a few more lessons in preventing breaches

The registerSecurityOct 27, 2025
Ravin Academy confirms the intrusion on Telegram, says student data was stolen Iran's school for state-sponsored cyberattackers admits it suffered a breach exposing the names and other personal information of its associates and students.…

Ex-CISA head thinks AI might fix code so fast we won't need security teams

The registerSecurityOct 27, 2025
Jen Easterly says most breaches stem from bad software, and smarter tech could finally clean it up Ex-CISA head Jen Easterly claims AI could spell the end of the cybersecurity industry, as the sloppy software and vulnerabilities that criminals rely on will be tracked down faster than ever.…

UN Cybercrime Treaty wins dozens of signatories, to go with its many critics

The registerSecurityOct 27, 2025
Allows surveillance and cross-border evidence sharing, which worries human rights groups The United Nations on Saturday staged a signing ceremony for the Convention against Cybercrime, the world’s first agreement to combat online crime. And while 72 nations picked up the pen, critics continue to p...

Sneaky Mermaid attack in Microsoft 365 Copilot steals data

The registerSecurityOct 24, 2025
Redmond says it's fixed this particular indirect prompt injection vuln updated  Microsoft fixed a security hole in Microsoft 365 Copilot that allowed attackers to trick the AI assistant into stealing sensitive tenant data – like emails – via indirect prompt injection attacks.…

Cyber exec with lavish lifestyle charged with selling secrets to Russia

The registerSecurityOct 24, 2025
The 0-days have left the building Federal prosecutors have charged a former general manager of US government defense contractor L3Harris's cyber arm Trenchant with selling secrets to an unidentified Russian buyer for $1.3 million.…

Playtime’s over: Crooks swipe Toys R Us Canada customer data and dump it online

The registerSecurityOct 23, 2025
What?! No complimentary credit monitoring? The Canadian outpost of retailer Toys R Us on Thursday notified customers that attackers accessed a database, stole some of their personal information, then posted the data online.…