News

Critical React Native Metro dev server bug under attack as researchers scream into the void

The Register - 1 hour 26 min ago
Too slow react-ion time

Baddies are exploiting a critical bug in React Native's Metro development server to deliver malware to both Windows and Linux machines, and yet the in-the-wild attacks still haven't received the "broad public acknowledgement" that they should, according to security researchers.…

Categories: News

CISA updated ransomware intel on 59 bugs last year without telling defenders

The Register - 3 hours 10 min ago
GreyNoise's Glenn Thorpe counts the cost of missed opportunities

On 59 occasions throughout 2025, the US Cybersecurity and Infrastructure Security Agency (CISA) silently tweaked vulnerability notices to reflect their use by ransomware crooks. Experts say that's a problem.…

Categories: News

X marks the raid: French cops swoop on Musk's Paris ops

The Register - 7 hours 18 min ago
Algorithmic bias probe continues, CEO and former boss summoned to defend the platform's corner

French police raided Elon Musk's X offices in Paris this morning as part of a criminal investigation into alleged algorithmic manipulation by foreign powers.…

Categories: News

Microsoft finally sends TLS 1.0 and 1.1 to the cloud retirement home

The Register - 7 hours 28 min ago
Azure Storage now requires version 1.2 or newer for encrypted connections

Today is the day Azure Storage stops supporting versions 1.0 and 1.1 of Transport Layer Security (TLS). TLS 1.2 is the new minimum.…

Categories: News

Polish cops bail 20-year-old bedroom botnet operator

The Register - 7 hours 53 min ago
DDoSer of 'strategically important' websites admitted to most charges

Polish authorities have cuffed a 20-year-old man on suspicion of carrying out DDoS attacks.…

Categories: News

DIY AI bot farm OpenClaw is a security 'dumpster fire'

The Register - 10 hours 13 min ago
Your own personal Jarvis. A bot to hear your prayers. A bot that cares. Just not about keeping you safe

OpenClaw, the AI-powered personal assistant users interact with via messaging apps and sometimes entrust with their credentials to various online services, has prompted a wave of malware and is delivering some shocking bills.…

Categories: News

British military to get legal OK to swat drones near bases

The Register - 10 hours 57 min ago
Armed Forces Bill would let troops take action against unmanned threats around defense sites

Britain's defense personnel will be given the authority to neutralize drones threatening military bases under measures being introduced in the Armed Forces Bill, currently making its way through Parliament.…

Categories: News

Notepad++ hijacking blamed on Chinese Lotus Blossom crew behind Chrysalis backdoor

The Register - Mon, 02/02/2026 - 23:23
The group targets telecoms, critical infrastructure - all the usual high-value orgs

Security researchers have attributed the Notepad++ update hijacking to a Chinese government-linked espionage crew called Lotus Blossom (aka Lotus Panda, Billbug), which abused weaknesses in the update infrastructure to gain a foothold in high-value targets by delivering a newly identified backdoor dubbed Chrysalis.…

Categories: News

StopICE hacked to send alarming text messages, admins accuse border patrol agent of sabotage

The Register - Mon, 02/02/2026 - 19:16
The ICE-tracking service says it doesn't store usernames or addresses

ICE-reporting service StopICE has blamed a US Customs and Border Protection (CBP) agent for attacking its app and website and sending users text messages warning them that their information had been "sent to the authorities."…

Categories: News

Russia-linked APT28 attackers already abusing new Microsoft Office zero-day

The Register - Mon, 02/02/2026 - 18:18
Ukraine’s CERT says the bug went from disclosure to active exploitation in days

Russia-linked attackers are already exploiting Microsoft's latest Office zero-day, with Ukraine's national cyber defense team warning that the same bug is being used to target government agencies inside the country and organizations across the EU.…

Categories: News

McDonald's is not lovin' your bigmac, happymeal, and mcnuggets passwords

The Register - Mon, 02/02/2026 - 17:05
Your favorite menu item might be easy to remember but it will not secure your account

Change Your Password Day took place over the weekend, and in case you doubt the need to improve this most basic element of cybersecurity hygiene, even McDonald's – yes, the fast food chain – is urging people to get more creative when it comes to passwords. …

Categories: News

OpenClaw patches one-click RCE as security Whac-A-Mole continues

The Register - Mon, 02/02/2026 - 14:10
Researchers disclose rapid exploit chain that let attackers run code via a single malicious web page

Security issues continue to pervade the OpenClaw ecosystem, formerly known as ClawdBot then Moltbot, as multiple projects patch bot takeover and remote code execution (RCE) exploits.…

Categories: News

Notepad++ update service hijacked in targeted state-linked attack

The Register - Mon, 02/02/2026 - 13:19
Breach lingered for months before stronger signature checks shut the door

A state-sponsored cyber criminal compromised Notepad++'s update service in 2025, according to the project's author.…

Categories: News

Infrastructure cyberattacks are suddenly in fashion. We can buck the trend

The Register - Mon, 02/02/2026 - 10:15
Don't be scared of the digital dark – learn how to keep the lights on

Opinion  Barely a month into 2026, electrical power infrastructure on two continents has tested positive for cyberattacks. One fell flat as attempts to infiltrate and disrupt the Polish distribution grid were rebuffed and reported. The other, earlier attack was part of Operation Absolute Resolve, the US abduction of Venezuela's President Maduro from Caracas on January 3.…

Categories: News

Why native cloud security falls short

The Register - Mon, 02/02/2026 - 08:00
Your cloud security must stand alone

Partner Content  As cloud adoption accelerates, many organizations are increasingly relying on the native security features offered by cloud service providers (CSPs). The ability to manage web application firewalls (WAF), data encryption, and key management (KMS) within a single provider ecosystem appears efficient and convenient. However, when security and reliability are viewed through the lens of enterprise risk management, this convenience may come at a significant cost.…

Categories: News

Open-source AI is a global security nightmare waiting to happen, say researchers

The Register - Sun, 01/02/2026 - 23:40
Also, South Korea gets a pentesting F, US Treasury says bye bye to BAH, North Korean hackers evolve, and more

Infosec in Brief  As if AI weren't enough of a security concern, now researchers have discovered that open-source AI deployments may be an even bigger problem than those from commercial providers. …

Categories: News

AI security startup CEO posts a job. Deepfake candidate applies, inner turmoil ensues.

The Register - Sun, 01/02/2026 - 14:14
'I did not think it was going to happen to me, but here we are'

Nearly every company, from tech giants like Amazon to small startups, has first-hand experience with fake IT workers applying for jobs - and sometimes even being hired. …

Categories: News

January blues return as Ivanti coughs up exploited EPMM zero-days

The Register - Fri, 30/01/2026 - 22:01
Consider yourselves compromised, experts warn

Ivanti has patched two critical zero-day vulnerabilities in its Endpoint Manager Mobile (EPMM) product that are already being exploited, continuing a grim run of January security incidents for enterprise IT vendors.…

Categories: News

Thousands more Oregon residents learn their health data was stolen in TriZetto breach

The Register - Fri, 30/01/2026 - 18:32
Parent company Cognizant hit with multiple lawsuits

Thousands more Oregonians will soon receive data breach letters in the continued fallout from the TriZetto data breach, in which someone hacked the insurance verification provider and gained access to its healthcare provider customers across multiple US states.…

Categories: News

Java developers want container security, just not the job that comes with it

The Register - Fri, 30/01/2026 - 00:12
BellSoft survey finds 48% prefer pre‑hardened images over managing vulnerabilities themselves

Java developers still struggle to secure containers, with nearly half (48 percent) saying they'd rather delegate security to providers of hardened containers than worry about making their own container security decisions.…

Categories: News

Pages

Subscribe to Sec Tec Limited aggregator - News