News
Even modest makeup can thwart facial recognition
Researchers at cyber-defense contractor PeopleTec have found that facial-recognition algorithms' focus on specific areas of the face opens the door to subtler surveillance avoidance strategies.…
Windows Patch Tuesday hits snag with Citrix software, workarounds published
Devices that have Citrix's Session Recording software installed are having problems completing this month's Microsoft Patch Tuesday update, which includes important fixes.…
Crypto klepto North Korea stole $659M over just 5 heists last year
North Korean blockchain bandits stole more than half a billion dollars in cryptocurrency in 2024 alone, the US, Japan, and South Korea say.…
Microsoft fixes under-attack privilege-escalation holes in Hyper-V
Patch Tuesday The first Patch Tuesday of 2025 has seen Microsoft address three under-attack privilege-escalation flaws in its Hyper-V hypervisor, plus plenty more problems that deserve your attention.…
FBI wipes Chinese PlugX malware from thousands of Windows PCs in America
The FBI, working with French cops, obtained nine warrants to remotely wipe PlugX malware from thousands of Windows-based computers that had been infected by Chinese government-backed criminals, according to newly unsealed court documents.…
Snyk appears to deploy 'malicious' packages targeting Cursor for unknown reason
Developer security company Snyk is at the center of allegations concerning the possible targeting or testing of Cursor, an AI code editor company, using "malicious" packages uploaded to NPM.…
It's not just Big Tech: The UK's Online Safety Act applies across the board
Analysis A little more than two months out from its first legal deadline, the UK’s Online Safety Act is causing concern among smaller online forums caught within its reach. The legislation, which came into law in the autumn of 2023, applies to search services and services that allow users to post content online or to interact with each other.…
UK floats ransomware payout ban for public sector
A total ban on ransomware payments across the public sector might actually happen after the UK government opened a consultation on how to combat the trend of criminals locking up whole systems and taxpayers footing the bill.…
Miscreants 'mass exploited' Fortinet firewalls, 'highly probable' zero-day used
Miscreants running a "mass exploitation campaign" against Fortinet firewalls, which peaked in December, may be using an unpatched zero-day vulnerability to compromise the equipment, according to security researchers who say they've observed the intrusions.…
Cryptojacking, backdoors abound as fiends abuse Aviatrix Controller bug
"Several cloud deployments" are already compromised following the disclosure of the maximum-severity vulnerability in Aviatrix Controller, researchers say.…
Microsoft sues 'foreign-based' cyber-crooks, seizes sites used to abuse AI
Microsoft has sued a group of unnamed cybercriminals who developed tools to bypass safety guardrails in its generative AI tools. The tools were used to create harmful content, and access to the tools were sold as a service to other miscreants.…
Azure, Microsoft 365 MFA outage locks out users across regions
Microsoft's multi-factor authentication (MFA) for Azure and Microsoft 365 (M365) was offline for four hours during Monday's busy start for European subscribers.…
NATO's newest member comes out swinging following latest Baltic Sea cable attack
Sweden has committed to sending naval forces into the Baltic Sea following yet another suspected Russian attack on underwater cables in the region.…
Ransomware crew abuses AWS native encryption, sets data-destruct timer for 7 days
A new ransomware crew dubbed Codefinger targets AWS S3 buckets and uses the cloud giant's own server-side encryption with customer provided keys (SSE-C) to lock up victims' data before demanding a ransom payment for the symmetric AES-256 keys required to decrypt it.…
Nominet probes network intrusion linked to Ivanti zero-day exploit
UK domain registry Nominet is investigating a potential intrusion into its network related to the latest Ivanti zero-day exploits.…
Europe coughs up €400 to punter after breaking its own GDPR data protection rules
Infosec in brief Gravy Analytics, a vendor of location intelligence info for marketers which reached a settlement with US authorities last year over its alleged unlawful sale of location, has reportedly been hacked – potentially exposing millions of smartphone users.…
Chinese cyber-spies peek over shoulder of officials probing real-estate deals near American military bases
Chinese cyber-spies who broke into the US Treasury Department also stole documents from officials investigating real-estate sales near American military bases, it's reported.…
Drug addiction treatment service admits attackers stole sensitive patient data
BayMark Health Services, one of the biggest drug addiction treatment facilities in the US, says it is notifying some patients this week that their sensitive personal information was stolen.…
Devs sent into security panic by 'feature that was helpful … until it wasn't'
On Call Velkomin, Vælkomin, Hoş geldin, and welcome to Friday, and therefore to another edition of On Call – The Register's end-of-week celebration of the tech support tasks you managed to tackle without too much trauma.…
Look for the label: White House rolls out 'Cyber Trust Mark' for smart devices
The White House this week introduced a voluntary cybersecurity labeling program for technology products so that consumers can have some assurance their smart devices aren't spying on them.…
Pages
