
Articles from www.theregister.com
Updated: 47 min 35 sec ago
Sun, 26/04/2026 - 10:28
Cal.com considers AGPL a license to drill, but not everyone feels that way
Opinion Cal.com has closed its commercial codebase, abandoning years of AGPL-3.0 licensing in a move that has alarmed the developer community that helped build it and sent ripples through the broader open source world.…
Sat, 25/04/2026 - 10:28
A previously unknown threat group using tried-and-tested social engineering tactics - Microsoft Teams chat invitations and helpdesk staff impersonation - is also using custom malware in its data-stealing attacks, according to Google's Threat Intelligence Group. The threat hunters say they spotted a "large email campaign" in late December 2025. The attack started by spamming target organizations with an overwhelming amount of email traffic. Then someone posing as helpdesk personnel would reach out via Microsoft Teams to offer help with the email volume. The fake helpdesk worker prompts the user to click a link that supposedly installs a local patch that prevents email spamming. This directs victims to a landing page masquerading as a "Mailbox Repair Utility" complete with a "Health Check" button that, when clicked, prompts users to authenticate using their email and password, allowing the attackers to nab them. The credential-harvest script also uses a sneaky "double-entry" psychological trick that auto-rejects the first and second password attempts as incorrect. "This serves two functions: it reinforces the user's belief that the system is legitimate and performs real-time validation, and it ensures that the attacker captures the password twice, significantly reducing the risk of a typo in the stolen data," according to GTIG. The phishing page then performs a fake mailbox integrity check, which keeps the victim engaged while credentials and metadata are sent to an attacker-controlled Amazon S3 bucket and staged files continue downloading onto the user's machine. "By the time the user receives a 'Configuration completed successfully' message, the attacker has secured the credentials and potentially established a persistent foothold on the endpoint using these staged files," the Googlers wrote. The first stage downloads an AutoHotKey binary and an AutoHotkey script, which immediately starts performing reconnaissance and installs a malicious Chromium browser extension called SnowBelt. (It's not available through the Chrome Web Store - only via social engineering tactics.) Snow malware UNC6692 uses the SnowBelt extension to download its other custom "Snow" named malware, along with additional AutoHotkey scripts, and a ZIP archive containing a portable Python executable and required libraries. The Snow malware, we're told, operates as a modular ecosystem with three primary components: SnowBelt, SnowGlaze, and SnowBasin. SnowBelt, a JavaScript-based backdoor delivered as a Chromium browser extension, gives the attacker an initial foothold and maintains persistence via the browser's extension registration system. It often hides behind names like "MS Heartbeat" or "System Heartbeat." SnowGlaze is a Python-based tunneler that runs in both Windows and Linux environments and manages the external communication. It creates an authenticated WebSocket tunnel between the victim's internal network and the attacker's command-and-control (C2) infrastructure, such as a Heroku subdomain. It also disguises malicious traffic by wrapping data in JSON objects and Base64 encoding it for transfer via WebSockets, which makes it look like legitimate, standard encrypted web traffic. Finally, SnowBasin is a Python bindshell providing interactive control over the infected system. It serves as a persistent backdoor, operating as a local HTTP server and typically listening on port 8000, allowing remote command execution, screenshot capture, and data staging for exfiltration. "This component is where active reconnaissance and mission completion occur," the threat hunters noted. "Attacker commands (such as whoami or net user) are sent through the SnowGlaze tunnel, intercepted by the SnowBelt extension, and then proxied to the SnowBasin local server via HTTP POST requests. SnowBasin executes these commands and relays the results back through the same pipeline to the attacker." These types of interactive social engineering tactics have proven very profitable for cybercrime groups like ShinyHunters and Scattered Lapsus$ Hunters. Google analysts, however, told The Register that there's no overlap between those crews and this new group, which it tracks as UNC6692. Google's analysis of UNC6692 and its Teams-led social engineering campaign follows a warning from Microsoft about criminals abusing Microsoft Teams communications and impersonating helpdesk personnel to snare users and then remotely control and infect victims' machines. Despite the similarities, Google's security researchers told us that the two campaigns don't seem to be related. They are a good reminder, though, of the increasing number of digital scammers using very convincing social engineering tactics alongside legitimate cloud services and tools to gain a foothold in organizations' IT environments. ®
Sat, 25/04/2026 - 10:28
Coming in cold with custom Snow malware
A previously unknown threat group using tried-and-tested social engineering tactics - Microsoft Teams chat invitations and helpdesk staff impersonation - is also using custom malware in its data-stealing attacks, according to Google's Threat Intelligence Group.…
Fri, 24/04/2026 - 17:03
Silicon often from US, but the kit from APAC and elsewhere
America's telco regulator has clarified its ban on foreign-made routers also includes mobile hotspots and domestic routers that use a 5G cellular connection to the internet.…
Fri, 24/04/2026 - 16:35
Carnival Corporation, the world's largest cruise company, is dealing with choppy waters after Have I Been Pwned flagged what it claimed were 7.5 million unique email addresses all allegedly tied to one of its subsidiaries. According to HIBP, the haul totals 8.7 million records and appears to relate to the Mariner Society loyalty program run by Holland America Line, a subsidiary of Carnival Corporation. It said the "data contained fields indicating it related to the Mariner Society loyalty program run by Holland America." The exposed data includes names, dates of birth, genders, and membership status details – the kind of personal data attackers can easily repurpose for fraud or phishing. The company acknowledged a security incident, according to HIBP, but its version of events is, for now, a lot more contained. Carnival says the breach involved a phishing attack against a single user account and said it is still working to understand the scope of any unauthorized access. That's not quite the story being told elsewhere. The data was published by the ever-busy ShinyHunters extortion crew, which claimed to have lifted not just customer data but "terabytes of internal corporate data" after talks with the company apparently went nowhere. "The company failed to reach an agreement with us despite our incredible patience," said a post on the group's leak site, seen by The Register, adding, "They don't care." Take the claims with the usual pinch of sea salt – ShinyHunters has form for dressing up its hits – but the volume and apparent legitimacy of the data flagged by HIBP suggest there is potentially something more substantial here than the usual leak site bravado. The Register has asked Carnival to confirm whether the figures match its own findings, what data was accessed, whether any ransom demand was made, and how attackers got in. It hadn't responded at the time of writing. ShinyHunters is no stranger to this kind of break-in, usually getting a foot in the door via phishing, stolen logins, or by cracking into SaaS platforms before digging around for anything they can cash in. If their claims are accurate, this went well beyond a single compromised inbox. Whether this turns out to be a contained phishing mishap or a full-blown data spill is still unclear – but either way, passengers may want to keep a closer eye on their inboxes than their next itinerary. ®
Fri, 24/04/2026 - 16:35
Leak-site bragging meets breach hunters as Have I Been Pwned flags millions of records
Carnival Corporation, the world's largest cruise company, is dealing with choppy waters after Have I Been Pwned flagged what it claimed were 7.5 million unique email addresses all allegedly tied to one of its subsidiaries. …
Fri, 24/04/2026 - 15:46
A US federal agency was successfully targeted by a previously unknown backdoor malware called Firestarter, according to CISA cybersnoops and their UK counterparts – neither of which disclosed the agency's name. FederalCivilianExecutiveBranch(FCEB)agencies include NASA; Homeland Security itself (cyberworkers at CISA are part of an operational unit in Homeland Security); the FBI; the DoJ; the IRS; the Department of Veteran Affairs; the Department of Health and Human Services (HHS); and more. Described as a backdoor with remote access capabilities, Firestarter was named after Cisco Secure Firewall Adaptive Security Appliance (ASA) and Cisco Secure Firewall Threat Defense (FTD), the two products the malware targeted. The CISA advisory states that only one FCEB agency was attacked with the malware, although it is suspected of being part of a wider campaign targeting government and critical national infrastructure networks in particular. Further, the lone incident CISA investigated so far involved a Cisco Firepower device running ASA software, although Secure Firewall devices are also thought to be susceptible to attack. Despite the perceived focus on government and critical national infrastructure, all organizations in the US and UK are advised to take preventative measures. CISA said Firestarter was especially sophisticated in that it maintained persistent access to compromised networking devices even after they were updated, allowing attackers to re-enter victims' networks without needing to exploit any new vulnerabilities. The malware was detected following routine continuous network monitoring. All organizations are advised to use YARA rules while carrying out memory analysis from device core dumps or disk images. Both CISA and its British counterparts at the National Cyber Security Centre (NCSC) want any organization that gets hit to collate all the evidence and submit it to them for intelligence-gathering purposes. The findings this week are an update to CISA's earlier advisory, warning of other attacks on Cisco products, ones that exploited CVE-2025-20333 (9.9) and CVE-2025-20362 (6.5). Likewise, Cisco is attributing the latest attacks to the same group it suspects was behind others from last year. Switchzilla tracks the group with the UAT-4356 identifier, but has consistently refused to attribute it to a nation-state, including any of the US's four primary geopolitical adversaries (China, Russia, Iran, North Korea), although it has said the group appears to be government-backed. The news of the federal agency's compromise comes just hours after intelligence agencies collectively issued a second warning this month about Chia's offensive cyber operations. Ten countries, including those in the Five Eyes alliance, were involved in the second warning of its kind in recent weeks, once again claiming that China was building covert networks, such as recruiting consumer-grade SOHO routers, to launch cyberattacks on adversaries. ®
Fri, 24/04/2026 - 15:46
Latest in long-running pwning of Cisco kit found in mystery Fed agency
A US federal agency was successfully targeted by a previously unknown backdoor malware called Firestarter, according to CISA cybersnoops and their UK counterparts – neither of which disclosed the agency's name.…
Fri, 24/04/2026 - 15:15
One way to deal with bug hunting LLMs: ditch the old drivers
One tactic to deal with LLM-powered vulnerability detection is simple – just speed up the removal of old code. If it's gone, it no longer matters if it's buggy.…
Fri, 24/04/2026 - 13:50
Intel is betting on AI to reverse its fortunes, wagering that inference and agentic workloads will restore the CPU to the center of compute - even as its chip manufacturing struggles persist. Speaking to analysts on its Q1 2026 earnings call, CEO Lip-Bu Tan said AI is pushing the total addressable chip market towards $1 trillion, and he reckons Intel is well placed to capture share. "For the last few years, the story around high-performance computing was almost exclusively about GPU and other accelerators. In recent months, we have seen clear signs that the CPU is reinserting itself as the indispensable foundation of the AI era," Lip-Bu said. AI is moving out of the data center and into the physical world, he added, with inference and learning workloads increasingly running on agents, robots, and edge devices. "I think the inference is going to be a much bigger market and the physical AI is another big market. So I think that's an opportunity for us... This is not just our wishful thinking, it is what we hear from our customers, and it is evident in the demand profile for our products." However, Intel needs to build the products in order to deliver on the promises, and the past several years have seen the chipmaker suffer delays to key chips and the cancellation of others, notably its most recent effort to build a credible GPU to challenge AMD and Nvidia in the AI training stakes. Lip-Bu says Chipzilla is making progress with its Intel 14A process node, one that it hopes will turn Intel's Foundry biz into a commercial success by producing chips for other companies as well as its own products. "We expect to see earlier design commitments emerge beginning in the second half of 2026 and expanding into the first half of 2027," he said, echoing comments by chief financial officer David Zinsner last month. Zinsner reported Q1 revenue of $13.6 billion, beating expectations, with AI-driven business lines accounting for 60 percent of that figure, up 40 percent year-on-year. He pointed to recent wins including Xeon 6 being selected as the host CPU for NVidia's DGX Rubin NVL8 systems as evidence that Intel is resurgent in the AI arena. Lip-Bu also referenced a recent long-term deal with Google for co-development of infrastructure processing units (IPUs) to offload networking and other tasks, saying: "This is a good example of how we win in AI infrastructure build-out. And then stay tuned - at the right time, we will announce other contracts." Zinsner added: "One statistic we look at is the ratio of CPUs to GPUs. And if you look at training solutions, they're generally running at 8 GPUs to 1 CPU. As we look into inference, it's probably getting into the 3 or 4 to 1 kind of level. And as you get into agentic and multi-agent, it's one potentially even flip in the other direction a little bit." Another potential AI win is with Elon Musk and his "Terafab" project, which aims to produce large volumes of AI chips - a terawatt's worth of computing power each year, in fact. Although Musk himself talked about this during Tesla's own earnings call this week, Lip-Bu was more tight-lipped when asked about it by an analyst. "Clearly, Elon and I believe that [the] global supply chain is not keeping pace with the rapid acceleration in the demand. And so we both share the vision that we're going to learn a lot together, exploring the innovative way in the process of the manufacturing," he said. "We'll update you when can." Whether you believe the AI hype or not, the stock market liked what it heard, and Intel's share price rose by as much as 20 per cent in after-hours trading, reaching a five year plus high. ®
Fri, 24/04/2026 - 13:50
Chipzilla hopes agents, robots, and edge devices make CPUs cool again... now it has to build the chips
Intel is betting on AI to reverse its fortunes, wagering that inference and agentic workloads will restore the CPU to the center of compute - even as its chip manufacturing struggles persist.…
Pages