The Register

Subscribe to The Register feed
Biting the hand that feeds IT — Enterprise Technology News and Analysis
Updated: 1 hour 42 min ago

More Cisco SD-WAN bugs battered in attacks

4 hours 12 min ago
CISA gives federal agencies 4 days to patch

America's lead cyber-defense agency has warned that three Cisco Catalyst SD-WAN Manager bugs are under attack, and given federal agencies just four days to patch the security holes.…

Categories: News

macOS ClickFix attacks deliver AppleScript stealers to snarf credentials, wallets

5 hours 53 min ago
Data from browsers, cryptocurrency wallets, 200+ extensions hoovered up

A ClickFix campaign targeting macOS users delivers an AppleScript-based infostealer that collects credentials and live session cookies from 14 browsers, 16 cryptocurrency wallets, and more than 200 extensions.…

Categories: News

Yet another ex-ransomware negotiator admits turning rogue after payoff from crimelords

7 hours 27 min ago
Plus: Court papers reveal nonprofit paid a ransom worth nearly $26.8 million

The third of three former ransomware negotiators accused of assisting the ALPHV/BlackCat ransomware gang in extorting US businesses has pleaded guilty, months after his two co-workers did the same.…

Categories: News

AI-assisted intruders pwned Vercel via OAuth abuse and a pilfered employee account

9 hours 25 min ago
CEO suspects silicon sidekick behind 'surprising velocity' breach - cyber crims shop stolen data for $2M

Vercel's CEO reckons the crooks behind its recent breach likely had a helping hand from AI, saying the attackers moved with "surprising velocity" and a deep understanding of the company's infrastructure.…

Categories: News

Crook claims to leak 'video surveillance footage' of companies

10 hours 12 min ago
Mexican IT services firm admits it was hacked, but says client operations weren't affected

A Mexican IT infrastructure and digital transformation biz is on clean-up duty after a criminal posted screenshots of what they claimed was company video surveillance footage to a cybercrime forum.…

Categories: News

Met police trials snoop tech platform in push to cuff more London shoplifters

10 hours 51 min ago
No facial recognition privacy intrusions either! Well, maybe a little

London's Metropolitan Police is trialing new retail technology to help curtail the city's pervasive shoplifting problem… and it doesn't rely on live facial recognition (LFR).…

Categories: News

Adaptavist Group breach spawns imposter emails as ransomware crew claims mega-haul

13 hours 12 min ago
Fake emails already doing the rounds as ransomware crew boasts about what it allegedly stole

UK enterprise software consultancy The Adaptavist Group is investigating a security breach after an intruder logged in with stolen credentials, while a ransomware crew claims it grabbed far more than the company is currently admitting.…

Categories: News

Panasonic creates device-locked QR codes to speed facial biometric capture

14 hours 5 min ago
Admins are tired of taking photos, so this enables secure on-site unattended enrolment

Japanese industrial giant Panasonic has created a new form of QR code it says will only work on designated devices and environments.…

Categories: News

Iran claims US used backdoors to knock out networking equipment during war

15 hours 21 min ago
And China is loving it

Iranian media is claiming that the US used backdoors and/or botnets to disable networking equipment during the current war, and Chinese state media is dining out on the allegations.…

Categories: News

Vibe coding upstart Lovable denies data leak, cites 'intentional behavior,' then throws HackerOne under the bus

22 hours 16 min ago
A lesson in how not to respond to vulnerability reports

Vibe-coding platform Lovable is pooh-poohing a researcher’s finding that anyone could open a free account on the service and read other users' sensitive info, including credentials, chat history, and source code. However, the company’s story keeps changing: First it attributed the publicly exposed info to "intentional behavior" and "unclear documentation," then threw bug-bounty service HackerOne under the bus.…

Categories: News

Claude Desktop changes app access settings for browsers you don't even have installed yet

Mon, 20/04/2026 - 20:56
Installation and pre-approval without consent looks dubious under EU law

One app should not modify another app without asking for and receiving your explicit consent. Yet Anthropic's Claude Desktop for macOS installs files that affect other vendors' applications without disclosure, even before those applications have been installed, and authorizes browser extensions without consent.…

Categories: News

Scot becomes second Scattered Spider-linked crook to plead guilty in US

Mon, 20/04/2026 - 18:22
Tyler Buchanan admits role in scheme that stole at least $8 million in virtual currency

A Scottish man linked to the Scattered Spider cybercrime crew has pleaded guilty in the US to a phishing and SIM-swap scheme that stole at least $8 million in cryptocurrency.…

Categories: News

Microsoft releases Windows Server update fix to fix its April update fixes

Mon, 20/04/2026 - 14:15
Out-of-band or out of control?

Microsoft has pushed out an out-of-band update to address the restart loop that hit some Windows Server devices after its April update.…

Categories: News

Next.js developer Vercel warns of customer credential compromise

Mon, 20/04/2026 - 08:31
Blames outfit called Context.ai, which reckons an agentic OAuth tangle caused the incident

Vercel, the company that created the open source Next.js web development framework, has a data leak that led to compromise of some customer credentials, and blamed an outfit called Context.ai for the mess.…

Categories: News

Just like phishing for gullible humans, prompt injecting AIs is here to stay

Mon, 20/04/2026 - 00:00
Aren't we all just prompting tokens of linguistic meaning and hoping the other person isn't bullshitting us?

kettle  It's a week of the year, which means there's been the discovery of yet another prompt injection attack that will force supposedly well-guarded AI bots to spill secrets by asking the right way. …

Categories: News

I meant to do that! AI vendors shrug off responsibility for vulns

Sun, 19/04/2026 - 12:07
Passing the buck, and the blame, down the road shows lack of AI companies' maturity

OPINION  AI vendors: "You need to use AI to fight AI threats (and do everything else in your corporate IT environment)." Also AI vendors: "That's not a security flaw; it's working as intended."…

Categories: News

CISA tells feds to patch 13-year-old Apache ActiveMQ bug under active attack

Fri, 17/04/2026 - 18:09
Bug hiding in plain sight for over a decade lands on KEV list

CISA is sounding the alarm on a newly-exploited Apache ActiveMQ bug, ordering federal agencies to patch within two weeks as attackers circle a flaw that's been quietly lurking for more than a decade.…

Categories: News

Opsec oopsie: Dutch navy frigate location outed by mailing it a Bluetooth tracker

Fri, 17/04/2026 - 17:31
Or, how public information and a €5 tracker exposed an avoidable opsec lapse

Militaries around the world spend countless hours training, developing policies, and implementing best operational security practices, so imagine the size of the egg on the face of the Dutch navy when journalists managed to track one of its warships for less than the cost of some hagelslag and a coffee.…

Categories: News

Locked-out iPhone user tells The Reg that Apple is scrambling to fix character flaw passcode bug

Fri, 17/04/2026 - 11:00
University student says he plans to move to Android, but concedes iOS engineers acting fast

Apple is finally working on a fix for a bug that has locked some users out of their iPhones for months, The Register understands.…

Categories: News

Claude Opus wrote a Chrome exploit for $2,283

Fri, 17/04/2026 - 08:02
Pause your Mythos panic because mainstream models anyone can use already pick holes in popular software

Anthropic withheld its Mythos bug-finding model from public release due to concerns that it would enable attackers to find and exploit vulnerabilities before anyone could react.…

Categories: News

Pages