The Register
Kubernetes overlords decide Ingress NGINX isn’t worth saving
Kubernetes maintainers have decided it’s not worth trying to save Ingress NGINX and will instead stop work on the project and retire it in March 2026.…
Chinese spies told Claude to break into about 30 critical orgs. Some attacks succeeded
Chinese cyber spies used Anthropic's Claude Code AI tool to attempt digital break-ins at about 30 high-profile companies and government organizations – and the government-backed snoops "succeeded in a small number of cases," according to a Thursday report from the AI company.…
Ransomed CTO falls on sword, refuses to pay extortion demand
Ransomware is a huge business, because affected orgs keep forking over money to get their data back. However, instead of paying a ransom demand after getting hit by extortionists last week, payment services provider Checkout.com donated the demanded amount to fund cybercrime research.…
Ubuntu 25.10's Rusty sudo holes quickly welded shut
Two vulnerabilities in Ubuntu 25.10's new "sudo-rs" command have been found, disclosed, and fixed in short order.…
Extra, extra, read all about it: Washington Post clobbered in Clop caper
The Washington Post has confirmed that nearly 10,000 employees and contractors had sensitive personal data stolen in the Clop-linked Oracle E-Business Suite (EBS) attacks.…
Rhadamanthys malware admin rattled as cops seize a thousand-plus servers
International cops have pulled apart the Rhadamanthys infostealer operation, seizing 1,025 servers tied to the malware in coordinated raids between November 10-13.…
NHS supplier ends probe into ransomware attack that contributed to patient death
Synnovis has finally wrapped up its investigation into the 2024 ransomware attack that crippled pathology services across London, ending an 18-month effort to untangle what the NHS supplier describes as one of the most complex data reconstruction jobs it has ever faced.…
Google sues 25 China-based scammers behind Lighthouse 'phishing for dummies' kit
Google has filed a lawsuit against 25 unnamed China-based scammers, which it claims have stolen more than 115 million credit card numbers in the US as part of the Lighthouse phishing operation.…
Attackers turned Citrix, Cisco 0-day exploits into custom-malware hellscape
An "advanced" attacker exploited CitrixBleed 2 and a max-severity Cisco Identity Services Engine (ISE) bug as zero-days to deploy custom malware, according to Amazon Chief Information Security Officer CJ Moses.…
Bitcoin bandit's £5B bubble bursts as cops wrap seven-year chase
The Metropolitan Police's seven-year investigation into a record-setting fraudster has ended after she was sentenced to 11 years and eight months in prison on Tuesday.…
UK's Cyber Security and Resilience Bill makes Parliamentary debut
UK government introduced the Cyber Security and Resilience (CSR) Bill to Parliament today, marking a significant overhaul of local cybersecurity legislation to sharpen the security posture of the most critical sectors.…
Aviation watchdog says organized drone attacks will shut UK airports ‘sooner or later’
Britain's aviation watchdog has warned it's only a matter of time before organized drone attacks bring UK airports to a standstill.…
China hates crypto and scams, but is now outraged USA acquired bitcoin from a scammer
China’s National Computer Virus Emergency Response Center (CVERC) has alleged a nation-state entity, probably the USA, was behind a 2020 attack on a bitcoin mining operation and by doing so has gone into bat for entities that Beijing usually blasts.…
Australia’s spy boss says authoritarian nations ready to commit ‘high-impact sabotage’
The head of Australia’s Security Intelligence Organisation (ASIO) has warned that authoritarian regimes “are growing more willing to disrupt or destroy critical infrastructure”, using cyber-sabotage.…
North Korean spies turn Google's Find Hub into remote-wipe weapon
North Korean state-backed spies have found a new way to torch evidence of their own cyber-spying – by hijacking Google's "Find Hub" service to remotely wipe Android phones belonging to their South Korean targets.…
EU's reforms of GDPR, AI slated by privacy activists for 'playing into Big Tech’s hands'
Privacy advocates are condemning the European Commission's leaked plans to overhaul digital privacy legislation, accusing officials of bypassing proper legislative processes to favor Big Tech interests.…
OWASP Top 10: Broken access control still tops app security list
The Open Worldwide Application Security Project (OWASP) just published its top 10 categories of application risks for 2025, its first list since 2021. It found that while broken access control remains the top issue, security misconfiguration is a strong second, and software supply chain issues are still prominent.…
Hitachi-owned GlobalLogic admits data stolen on 10k current and former staff
Digital engineering outfit GlobalLogic says personal data from more than 10,000 current and former employees was exposed in the wave of Oracle E-Business Suite (EBS) attacks attributed to the Clop ransomware gang. The Hitachi-owned biz joins a growing roster of high-profile victims that also now includes The Washington Post and Allianz UK.…
UK asks cyberspies to probe whether Chinese buses can be switched off remotely
UK governmental is working with the National Cyber Security Centre to understand and "mitigate" any risk that China-made imported electric buses could be remotely accessed and potentially disabled.…
Cyber insurers paid out over twice as much for UK ransomware attacks last year
The number of successful cyber insurance claims made by UK organizations shot up last year, according to the latest figures from the industry's trade association.…