The Register
Substack says intruder lifted emails, phone numbers in months-old breach
Newsletter platform Substack has admitted that an intruder swiped user contact details months before the company noticed, forcing it to warn writers and readers that their email addresses and other account metadata were accessed without permission.…
Asia-based government spies quietly broke into critical networks across 37 countries
A state-aligned cyber group in Asia compromised government and critical infrastructure organizations across 37 countries in an ongoing espionage campaign, according to security researchers.…
Betterment breach may expose 1.4M users after social engineering attack
Breach-tracking site Have I Been Pwned (HIBP) claims a cyberattack on Betterment affected roughly 1.4 million users – although the investment company has yet to publicly confirm how many customers were affected by January's intrusion.…
Italy claims cyberattacks 'of Russian origin' are pelting Winter Olympics
Italy's foreign minister says the country has already started swatting away cyberattacks from Russia targeting the Milano Cortina Winter Olympics.…
n8n security woes roll on as new critical flaws bypass December fix
Multiple newly disclosed bugs in the popular workflow automation tool n8n could allow attackers to hijack servers, steal credentials, and quietly disrupt AI-driven business processes.…
Cloud sovereignty is no longer just a public sector concern
Interview Sovereignty remains a hot topic in the tech industry, but interpretations of what it actually means – and how much it matters – vary widely between organizations and sectors. While public bodies are often driven by regulation and national policy, the private sector tends to take a more pragmatic, cost-focused view.…
Three clues that your LLM may be poisoned with a sleeper-agent back door
Sleeper agent-style backdoors in AI large language models pose a straight-out-of-sci-fi security threat.…
Satya Nadella decides Microsoft needs an engineering quality czar
Microsoft CEO Satya Nadella has decided Microsoft needs an engineering quality czar, and shifted Charlie Bell, the company’s executive veep for security, into the new role.…
AWS intruder achieved admin access in under 10 minutes thanks to AI assist, researchers say
A digital intruder broke into an AWS cloud environment and in just under 10 minutes went from initial access to administrative privileges, thanks to an AI speed assist.…
Critical SolarWinds Web Help Desk bug under attack
Attackers are exploiting a critical SolarWinds Web Help Desk bug - less than a week after the vendor disclosed and fixed the 9.8-rated flaw. That's according to America's lead cyber-defense agency, which set a Friday deadline for federal agencies to patch the security flaw.…
Nitrogen ransomware is so broken even the crooks can't unlock your files
Cybersecurity experts usually advise victims against paying ransomware crooks, but that advice goes double for those who have been targeted by the Nitrogen group. There's no way to get your data back from them!…
Universal £7,500 payout offered to PSNI staff over major data breach
Police Service of Northern Ireland (PSNI) employees who had their details exposed in a significant 2023 data breach will each receive £7,500 ($10,279) as part of a universal offer of compensation.…
Clouds rush to deliver OpenClaw-as-a-service offerings
If you’re brave enough to want to run the demonstrably insecure AI assistant OpenClaw, several clouds have already started offering it as a service.…
AI agents can't yet pull off fully autonomous cyberattacks - but they are already very helpful to crims
AI agents and other systems can't yet conduct cyberattacks fully on their own - but they can help criminals in many stages of the attack chain, according to the International AI Safety report.…
Critical React Native Metro dev server bug under attack as researchers scream into the void
Baddies are exploiting a critical bug in React Native's Metro development server to deliver malware to both Windows and Linux machines, and yet the in-the-wild attacks still haven't received the "broad public acknowledgement" that they should, according to security researchers.…
CISA updated ransomware intel on 59 bugs last year without telling defenders
On 59 occasions throughout 2025, the US Cybersecurity and Infrastructure Security Agency (CISA) silently tweaked vulnerability notices to reflect their use by ransomware crooks. Experts say that's a problem.…
X marks the raid: French cops swoop on Musk's Paris ops
French police raided Elon Musk's X offices in Paris this morning as part of a criminal investigation into alleged algorithmic manipulation by foreign powers.…
Microsoft finally sends TLS 1.0 and 1.1 to the cloud retirement home
Today is the day Azure Storage stops supporting versions 1.0 and 1.1 of Transport Layer Security (TLS). TLS 1.2 is the new minimum.…
Polish cops bail 20-year-old bedroom botnet operator
Polish authorities have cuffed a 20-year-old man on suspicion of carrying out DDoS attacks.…
DIY AI bot farm OpenClaw is a security 'dumpster fire'
OpenClaw, the AI-powered personal assistant users interact with via messaging apps and sometimes entrust with their credentials to various online services, has prompted a wave of malware and is delivering some shocking bills.…