The Register
HMRC: Crooks broke into 100k accounts, stole £43M from British taxpayer in late 2024
The UK's tax collections agency says cyberbaddies defrauded it of £47 million ($63 million) late last year, but insists the criminal case was not a cyberattack.…
AI kept 15-year-old zombie vuln alive, but its time is drawing near
A security bug that surfaced fifteen years ago in a public post on GitHub has survived developers' attempts on its life.…
China accuses Taiwan of running five feeble APT gangs, with US help
Beijing complains it’s under relentless attack by the equivalent of an ant trying to shake a tree China’s National Computer Virus Emergency Response Center on Thursday published a report in which it claims Taiwan targeted it with a years-long but feeble cyber offensive, backed by the USA.…
IBM Cloud login breaks for second time this week and Big Blue isn't saying why
IBM isn’t having its best week after the company experienced another cloudy outage and a critical-rated vulnerability.…
Play ransomware crims exploit SimpleHelp flaw in double-extortion schemes
Groups linked with the Play ransomware have exploited more than 900 organizations, the FBI said Wednesday, and have developed a number of new techniques in their double-extortion campaigns - including exploiting a security flaw in remote-access tool SimpleHelp if orgs haven't patched it.…
Ukraine strikes Russian bomber-maker with hack attack
Following a daring drone attack on Russian airfields, Ukrainian military intelligence has reportedly also hacked the servers of Tupolev, the Kremlin's strategic bomber maker.…
Ransomware scum leak patient data after disrupting chemo treatments at Kettering
Kettering Health patients who had chemotherapy sessions and pre-surgery appointments canceled due to a ransomware attack in May now have to deal with the painful prospect that their personal info may have been leaked online.…
Fake IT support calls hit 20 orgs, end in stolen Salesforce data and extortion, Google warns
A group of financially motivated cyberscammers who specialize in Scattered-Spider-like fake IT support phone calls managed to trick employees at about 20 organizations into installing a modified version of Salesforce's Data Loader that allows the crims to steal sensitive data.…
Crims stole 40,000 people's data from our network, admits publisher Lee Enterprises
Regional newspaper publisher Lee Enterprises says data belonging to around 40,000 people was stolen during an attack on its network earlier this year.…
UK CyberEM Command to spearhead new era of armed conflict
Revealing more details about the Cyber and Electromagnetic (CyberEM) military domain, the UK's Ministry of Defence (MoD) says "there are pockets of excellence" but improvements must be made to ensure the country's capability meets the needs of national defense.…
Ukraine war spurred infosec vet Mikko Hyppönen to pivot to drones
Interview Mikko Hyppönen has spent the last 34 years creating security software that defends against criminals and state-backed actors, but now he's moving onto drone warfare.…
‘Deliberate attack’ deletes shopping app’s AWS and GitHub resources
The CEO of Indian grocery ordering app KiranaPro has claimed an attacker deleted its GitHub and AWS resources in a targeted and deliberate attack and vowed to name the perpetrator.…
Meta pauses mobile port tracking tech on Android after researchers cry foul
Security researchers say Meta and Yandex used native Android apps to listen on localhost ports, allowing them to link web browsing data to user identities and bypass typical privacy protections.…
You say Cozy Bear, I say Midnight Blizzard, Voodoo Bear, APT29 …
Opinion Microsoft and CrowdStrike made a lot of noise on Monday about teaming up with other threat-intel outfits to "bring clarity to threat-actor naming."…
Google quietly pushes emergency fix for Chrome 0-day as exploit runs wild
Google revealed Monday that it had quietly deployed a configuration change last week to block active exploitation of a Chrome zero-day.…
X's new 'encrypted' XChat feature seems no more secure than the failure that came before it
Elon Musk's X social media platform is rolling out a new version of its direct messaging feature that the platform owner said had a "whole new architecture," but as with many a Muskian proclamation, there's reason to doubt what's been said. …
Crooks fleece The North Face accounts with recycled logins
Joining the long queue of retailers dealing with cyber mishaps is outdoorsy fashion brand The North Face, which says crooks broke into some customer accounts using login creds pinched from breaches elsewhere.…
Microsoft patches the patch that put Windows 11 in a coma
Microsoft is patching another patch that dumped some PCs into recovery mode with an unhelpful error code.…
Illicit crypto-miners pouncing on lazy DevOps configs that leave clouds vulnerable
Up to a quarter of all cloud users are at risk of having their computing resources stolen and used to illicitly mine for cryptocurrency, after crims cooked up a campaign that targets publicly accessible DevOps tools.…
Bling slinger Cartier tells customers to be wary of phishing attacks after intrusion
Global jewelry giant Cartier is writing to customers to confirm their data was exposed to cybercriminals that broke into its systems.…