The Register

Subscribe to The Register feed
Biting the hand that feeds IT — Enterprise Technology News and Analysis
Updated: 1 hour 7 min ago

What the Plex? Streaming service suffers yet another password spill

Tue, 09/09/2025 - 14:45
For the third time in a decade

Streaming platform Plex is warning some users to reset their passwords after suffering yet another breach.…

Categories: News

Nokia successor HMD spawns secure device biz with Euro-made smartphone

Tue, 09/09/2025 - 11:15
Ivalo XE handset targets governments and security critical sectors, though Qualcomm silicon keeps it tied to the US

Finnish phone maker HMD Global is launching a business unit called HMD Secure to target governments and other security-critical customers, and has its first device ready to go.…

Categories: News

Anthropic's Claude Code runs code to test if it is safe – which might be a big mistake

Tue, 09/09/2025 - 10:30
AI security reviews add new risks, say researchers

App security outfit Checkmarx says automated reviews in Anthropic's Claude Code can catch some bugs but miss others – and sometimes create new risks by executing code while testing it.…

Categories: News

UK toughens Online Safety Act with ban on self-harm content

Tue, 09/09/2025 - 07:29
Charities welcome change, but critics warn the law is already too broad

Tech companies will be legally required to prevent content involving self-harm from appearing on their platforms – rather than responding and removing it – in a planned amendment to the UK's controversial Online Safety Act.…

Categories: News

Forget disappearing messages – now Signal will store 100MB of them for you for free

Tue, 09/09/2025 - 04:33
Including messages sent to users, a potential problem for the privacy-conscious

Encrypted messaging app Signal is rolling out a free storage system for its users, with extra space if folks are willing to pay for it.…

Categories: News

WhatsApp's former security boss claims reporting infosec failings led to ousting

Tue, 09/09/2025 - 00:36
Meta shrugs off allegations of improper dismissal, ignoring privacy and security

WhatsApp's former head of security, Attaullah Baig, has filed a lawsuit against its parent company, Meta, alleging that the social media megalith retaliated against him for reporting security failings that violated legal commitments.…

Categories: News

The US government has no idea how many cybersecurity pros it employs

Mon, 08/09/2025 - 22:02
Auditors find federal cybersecurity workforce data messy, incomplete, and unreliable

The US federal government employs tens of thousands of cybersecurity professionals at a cost of billions per year – or at least it thinks it does, as auditors have found the figures are incomplete and unreliable. …

Categories: News

Drift massive attack traced back to loose Salesloft GitHub account

Mon, 08/09/2025 - 20:52
Meanwhile the victim count grows

The Salesloft Drift breach that compromised "hundreds" of companies including Google, Palo Alto Networks, and Cloudflare, all started with miscreants gaining access to the Salesloft GitHub account in March.…

Categories: News

Dev snared in crypto phishing net, 18 npm packages compromised

Mon, 08/09/2025 - 20:06
Popular npm packages debug, chalk, and others hijacked in massive supply chain attack

Crims have added backdoors to at least 18 npm packages after developer Josh Junon inadvertently authorized a reset of the two-factor authentication protecting his npm account.…

Categories: News

Salt Typhoon used dozens of domains, going back five years. Did you visit one?

Mon, 08/09/2025 - 18:47
Plus ties to the Chinese spies who hacked Barracuda email gateways

Security researchers have uncovered dozens of domains used by Chinese espionage crew Salt Typhoon to gain stealthy, long-term access to victim organizations going back as far as 2020.…

Categories: News

PACER buckles under MFA rollout as courts warn of support delays

Mon, 08/09/2025 - 14:15
Busy lawyers on hold for five hours as staff handhold users into deploying the security measure

US courts have warned of delays as PACER, the system for accessing court documents, struggles to support users enrolling in its mandatory MFA program.…

Categories: News

CISA sounds alarm over TP-Link wireless routers under attack

Mon, 08/09/2025 - 12:46
Plus: Google clears up Gmail concerns, NSA drops SBOM bomb, Texas sues PowerSchool, and more

Infosec in brief  The US Cybersecurity and Infrastructure Security Agency (CISA) has said two flaws in routers made by Chinese networking biz TP-Link are under active attack and need to be fixed – but there's another flaw being exploited as well.…

Categories: News

UK tech minister booted out in weekend cabinet reshuffle

Mon, 08/09/2025 - 12:20
Fallout from latest political drama sparks a changing of the guard

UK prime minister Sir Keir Starmer cleared out the officials in charge of tech and digital law in a dramatic cabinet reshuffle at the weekend.…

Categories: News

The crazy, true story behind the first AI-powered ransomware

Fri, 05/09/2025 - 21:11
tldr; boffins did it

interview  It all started as an idea for a research paper. …

Categories: News

Shell to pay: Crims invade your PC with CastleRAT malware, now in C and Python

Fri, 05/09/2025 - 20:45
Pro tip, don't install PowerShell commands without approval

A team of data thieves has doubled down by developing its CastleRAT malware in both Python and C variants. Both versions spread by tricking users into pasting malicious commands through a technique called ClickFix, which uses fake fixes and login prompts.…

Categories: News

Critical, make-me-super-user SAP S/4HANA bug under active exploitation

Fri, 05/09/2025 - 19:04
9.9-rated flaw on the loose, so patch now

A critical code-injection bug in SAP S/4HANA that allows low-privileged attackers to take over your SAP system is being actively exploited, according to security researchers.…

Categories: News

Knock-on effects of software dev break-in hit schools trust

Fri, 05/09/2025 - 09:30
Affinity Learning Partnership warns staff after Intradev breach

A major UK education trust has warned staff that their personal information may have been compromised following a cyberattack on software developer Intradev in August.…

Categories: News

Attackers snooping around Sitecore, dropping malware via public sample keys

Fri, 05/09/2025 - 00:14
You cut and pasted the machine key from the official documentation? Ouch

Unknown miscreants are exploiting a configuration vulnerability in multiple Sitecore products to achieve remote code execution via a publicly exposed key and deploy snooping malware on infected machines.…

Categories: News

Boffins build automated Android bug hunting system

Thu, 04/09/2025 - 23:18
AI agent system said to have found more than 100 zero-day flaws in production apps

AI models get slammed for producing sloppy bug reports and burdening open source maintainers with hallucinated issues, but they also have the potential to transform application security through automation.…

Categories: News

China-aligned crew poisons Windows servers to manipulate Google results

Thu, 04/09/2025 - 21:57
Defrauding search with custom malware, Potato-family exploits

A new China-aligned cybercrime crew named GhostRedirector has compromised at least 65 Windows servers worldwide - spotted in a June internet scan - using previously undocumented malware to juice gambling sites' rankings in Google search, according to ESET researchers.…

Categories: News

Pages