The Register
Cops back Dutch telco Odido after second wave of ShinyHunters leaks
The Netherlands' national police is backing Odido's refusal to pay a ransom after ShinyHunters leaked a second round of records belonging to the telco.…
Rapid AI-driven development makes security unattainable, warns Veracode
Veracode has posted its annual State of Software Security report, based on data from 1.6 million applications tested on its cloud platform, finding that more vulnerabilities are being created than are being fixed, and that high-velocity development with AI is making comprehensive security unattainable.…
Scattered Lapsus$ Hunters auditioning female voices to sharpen social engineering
Prolific cybercrime crew Scattered Lapsus$ Hunters (SLSH) is reportedly recruiting women in the hope of improving its social engineering success.…
Five Eyes warn: Patch your Cisco SD-WAN or risk root takeover
The Five Eyes intelligence alliance is urgently warning defenders to patch two Cisco Catalyst SD-WAN vulnerabilities used in attacks.…
Claude collaboration tools left the door wide open to remote code execution
Security vulnerabilities in Claude Code could have allowed attackers to remotely execute code on users' machines and steal API keys by injecting malicious configurations into repositories, and then waiting for a developer to clone and open an untrustworthy project.…
Google catches Beijing spies using Sheets to spread espionage across 4 continents
A China-linked crew found a unique formula for attacking telcos and government orgs across the Americas, Asia, and Africa in its latest round of intrusions. Google's threat intelligence, along with unnamed industry partners, disrupted the gang, which used the Chocolate Factory's own spreadsheet tools as part of its exploits.…
Fake 'interview' repos lure Next.js devs into running secret-stealing malware
Next.js developers are once again in the crosshairs as hackers seed malicious repositories disguised as legitimate projects, according to Microsoft, which said a limited set of those repos were directly tied to observed compromises.…
Ex-L3Harris exec jailed 7 years for selling exploits to Russia
The former general manager of L3Harris's cyber arm will spend the next seven years behind bars for selling trade secrets to Russia.…
Wynn Resorts takes attacker's word for it that stolen staff data was deleted
Wynn Resorts has confirmed that employee data was stolen from its servers, and is taking the hackers' word that they've since deleted it.…
OpenAI says Chinese cops used ChatGPT to plan and track smear ops against opponents
A ChatGPT user with links to Chinese law enforcement tried to use the AI chatbot to run smear campaigns targeting the Japanese prime minister and other critics of the Chinese Communist Party, according to OpenAI's latest report on malicious uses of its models.…
Threat intelligence supply chain is full of weak links, researchers find
Researchers from Georgia Tech have found that the supply chain for threat intelligence data is susceptible to adversarial action, and proposed a method to improve data sharing that they think will make it stronger.…
AI has gotten good at finding bugs, not so good at swatting them
What good is finding a hole if you can't fix it? Anthropic last week talked up Claude Code's improved ability to find software vulnerabilities and propose patches. But security researchers say that's not enough.…
Patch these 4 critical, make-me-root SolarWinds bugs ASAP
If you run SolarWinds’ Serv-U, you should patch promptly. Four critical vulnerabilities in the file transfer software can allow attackers to execute code as root.…
North Korea's Lazarus Group targets healthcare orgs with Medusa ransomware
North Korea’s Lazarus Group appears to have added another tool to its kit. It has begun using Medusa ransomware in extortion attacks targeting at least one US healthcare organization and an unnamed victim in the Middle East, according to Symantec and Carbon Black threat hunters.…
Go library maintainer brands GitHub's Dependabot a 'noise machine'
A Go library maintainer has urged developers to turn off GitHub's Dependabot, arguing that false positives from the dependency-scanning tool "reduce security by causing alert fatigue."…
UK data watchdog fines Reddit £14.47M for letting kids slip past the gate
The UK's data protection regulator has fined social media giant Reddit £14.47 million ($19.5 million) over its use of children's data.…
Korean cops charge teens over bike hire breach that exposed data on 4.62M riders
Two South Korean teenagers were this week charged with breaching Seoul's public bike service, Ttareungyi.…
UK tech hit by double trouble: Fewer foreign boffins amid skills squeeze
The number of international workers applying for a visa to work in the UK's tech sector dropped 11 percent between Q2 and Q3 2025, and was down 6 percent year-on-year, according to consultancy RSM UK.…
Euro allies aiming to rapidly build low-cost air defense weapons
Britain has joined a handful of European allies in a program to develop low-cost air defense systems, including autonomous drones or missiles, with project delivery of the first elements scheduled for as early as 2027.…
Infosec community panics as Anthropic rolls out Claude code security checker
ai-pocalypse Anthropic sent the infosec community into a tizzy on Friday when it rolled out Claude Code Security, a new feature that scans codebases for vulnerabilities and suggests patches to fix the issues.…