News

Cisco warns of two more SD-WAN bugs under active attack

The Register - 58 min 36 sec ago
Switchzilla says flaws could allow file overwrites or privilege escalation

Just when network admins thought the Cisco SD-WAN patch queue might finally be shrinking, Switchzilla has confirmed miscreants are exploiting more vulnerabilities in its SD-WAN management software.…

Categories: News

Microsoft spots ClickFix campaign getting users to self-pwn on Windows Terminal

The Register - 2 hours 26 min ago
Crooks tweak familiar copy-paste ruse so that victims run malicious commands themselves

A new twist on the long-running ClickFix scam is now tricking Windows users into launching Windows Terminal and pasting malware into it themselves – handing the credential-stealing Lumma infostealer the keys to their browser vault.…

Categories: News

Son of government contractor arrested after alleged $46M crypto heist from US Marshals

The Register - 4 hours 29 sec ago
FBI and French GIGN swoop on Saint Martin, John Daghita in cuffs

The son of a government contractor was arrested in the Caribbean after allegedly stealing more than $46 million in seized cryptocurrency from the US Marshals Service, the FBI says.…

Categories: News

Microsoft finally gets around to fixing Windows 10 Recovery Environment after breaking it in October

The Register - 4 hours 25 min ago
Released from the curse of the update bork fairy

Microsoft has finally fixed a Windows Recovery Environment (WinRE) bug it introduced in Windows 10's final update.…

Categories: News

Transport for London says 2024 breach affected 7M customers, not 5,000

The Register - 5 hours 41 min ago
Attackers accessed systems holding data tied to millions of Oyster and contactless users

Transport for London has confirmed that a 2024 breach exposed the data of more than 7 million people – a far larger crowd than the few thousand customers originally warned that their details might be at risk.…

Categories: News

Google says spyware makers and China-linked groups dominated zero-day attacks last year

The Register - Thu, 05/03/2026 - 23:52
Of the 90 zero-days GTIG tracked in 2025, 43 hit enterprise tech

Zero-day exploitation targeting enterprise tech products reached an all-time high last year, with China-linked cyber-espionage groups remaining the most prolific state-backed users, according to Google.…

Categories: News

Iran intelligence backdoored US bank, airport, software outfit networks

The Register - Thu, 05/03/2026 - 18:53
MOIS-linked MuddyWater crew has a new, custom implant

An Iranian cyber crew believed to be part of the Iranian Ministry of Intelligence and Security (MOIS) has been embedded in multiple US companies' networks - including a bank, software firm, and airport, among others - since the beginning of February, with more activity in the days following the US and Israeli military strikes, according to security researchers.…

Categories: News

UK watchdog eyes Meta's smart glasses after workers say they 'see everything'

The Register - Thu, 05/03/2026 - 12:18
Contractors tasked with improving AI reportedly had access to intimate footage captured through wearables

Britain's privacy watchdog is asking questions about Meta's AI-powered smart glasses after reports that human contractors reviewing recordings from the devices were exposed to extremely private moments captured by unsuspecting users.…

Categories: News

'Hundreds' of Iranian hacking attempts have hit surveillance cameras since the missile strikes

The Register - Wed, 04/03/2026 - 23:59
Attack infrastructure attributed to 'several Iran-nexus threat actors'

Multiple Iranian hacking crews have been targeting internet-connected surveillance cameras across Israel and other Middle Eastern countries since the war started on February 28, according to Check Point security researchers. …

Categories: News

Malware-laced OpenClaw installers get Bing AI search boost

The Register - Wed, 04/03/2026 - 20:50
Think before you download

OpenClaw, the AI agent that can manage just about anything, is risky all by itself, but now fake installers for it are wreaking havoc. Users who searched Bing’s AI results for “OpenClaw Windows” were directed to a malicious GitHub repository that delivered information stealers and GhostSocks onto their machines.…

Categories: News

LexisNexis confirms data breach at Legal & Professional arm, some customer records affected

The Register - Wed, 04/03/2026 - 16:04
Crooks claim 2 GB haul from AWS instance via React2Shell exploit

Data analytics giant LexisNexis has confirmed its Legal & Professional division suffered a data breach days after the Fulcrumsec cybercrime crew claimed responsibility for the hack.…

Categories: News

Kaspersky dismisses claims Coruna iPhone exploit kit is connected to NSA-linked operation

The Register - Wed, 04/03/2026 - 14:18
Follows suggestions iPhone-pwning toolset bears hallmarks of zero-days that targeted Russian diplomats

Russian cybersecurity outfit Kaspersky is waving away claims that an iPhone exploit kit recently uncovered by Google was developed by the same people who were behind a group of zero-days that allegedly compromised thousands of Russian diplomats in a 2023 campaign.…

Categories: News

Google feels the need for security speed, so will ship Chrome updates every two weeks

The Register - Wed, 04/03/2026 - 02:01
Retains eight-weekly Extended Stable releases but warns fortnightly updates are the best way to stay safe

Google will halve the time between releases of its Chrome browser to two weeks, across versions of the software for desktop operating systems, Android, and iOS.…

Categories: News

Dev stunned by $82K Gemini bill after unknown API key thief goes to town

The Register - Tue, 03/03/2026 - 23:19
Probably not an isolated incident only as researchers have already found 2,863 live API keys exposed

A developer says their company is on the hook for more than $82,000 in unauthorized charges after a stolen Google Gemini API key racked massive usage costs up in just 48 hours.…

Categories: News

Chat at your own risk! Data brokers are selling deeply personal bot transcripts

The Register - Tue, 03/03/2026 - 20:59
AI conversations for sale include sensitive health and legal details

Your latest chat transcript could be bought and sold. Data brokers are selling access to sensitive personal data captured during chatbot conversations, despite claims that the data is anonymized and obtained with consent.…

Categories: News

Cyberwarriors elevated to big leagues in US war with Iran

The Register - Tue, 03/03/2026 - 18:23
No more hiding in the server closet: Cyber ops mentioned alongside kinetic warfare as critical to conflict

In what may be the most public acknowledgment of its cyber operations capabilities to date, the Pentagon has admitted that cyber soldiers are playing a key role in its attacks on Iran. …

Categories: News

Turns out most cybercriminals are old enough to know better

The Register - Tue, 03/03/2026 - 15:25
Law enforcement data shows profit-driven cybercrime is dominated by 35- to 44-year-olds, not script kiddies

Contrary to what some believe, cybercrime is not a kids' game. Middle-aged adults, not teenagers, now make up the biggest chunk of people getting busted.…

Categories: News

Until last month, attackers could've stolen info from Perplexity Comet users just by sending a calendar invite

The Register - Tue, 03/03/2026 - 14:01
AI browsing agent left local files open for the taking

If you wanted to steal local files from someone using Perplexity's Comet browser, until last month you could just schedule the theft by sending your victim a calendar event.…

Categories: News

Chrome Gemini panel became privilege escalator for rogue extensions

The Register - Tue, 03/03/2026 - 11:39
High-severity flaw let malicious add-ons access system via browser's embedded AI feature

Security boffins have discovered a high-severity bug in Google Chrome that allowed malicious extensions to hijack its Gemini Live AI panel and inherit privileges they were never meant to have.…

Categories: News

Cybercriminals swipe 15.8M medical records from French doctors ministry

The Register - Tue, 03/03/2026 - 11:00
Third-party software supplier breached leading to leak of notes

Around 15.8 million administrative files were stolen after attackers breached a software supplier to France's health ministry.…

Categories: News

Pages

Subscribe to Sec Tec Limited aggregator - News