The Register
PayPal app code error leaked personal info and a 'few' unauthorized transactions
PayPal has notified about 100 customers that their personal information was exposed online during a code change gone awry, and in a few of these cases, people saw unauthorized transactions on their accounts.…
AI coding assistant Cline compromised to create more OpenClaw chaos
Someone compromised open source AI coding assistant Cline CLI's npm package earlier this week in an odd supply chain attack that secretly installed OpenClaw on developers' machines without their knowledge. …
ShinyHunters demands $1.5M not to leak Vegas casino and resort chain data
Las Vegas hotel and casino giant Wynn Resorts appears to be the latest victim of data-grabbing and extortion gang ShinyHunters.…
Ukrainian gets five years for helping North Koreans secure US tech jobs
Ukrainian national Oleksandr Didenko will spend the next five years behind bars in the US for his involvement in helping North Korean IT workers secure fraudulent employment.…
Founder ditches AWS for Euro stack, finds sovereignty isn't plug-and-play
Building a startup entirely on European infrastructure sounds like a nice sovereignty flex right up until you actually try it and realize the real price gets paid in time, tinkering, and slowly unlearning a decade of GitHub muscle memory.…
CISA gives federal agencies three days to patch actively exploited Dell bug
Uncle Sam's cyber defenders have given federal agencies just three days to patch a maximum-severity Dell bug that's been under active exploitation since at least mid-2024.…
Ex-Google engineers accused of helping themselves to chip security secrets
Two former Google engineers and a third alleged accomplice are facing federal charges after prosecutors accused them of swiping sensitive chip and security technology secrets and then trying to cover their tracks when the scheme began to unravel.…
Attackers have 16-digit card numbers, expiry dates, but not names. Should org get £500k fine?
The UK's data protection watchdog has scored a small win in a lengthy legal battle against a British retail group that lost millions of data records during a 2017 breach.…
Snyk CEO bails, wants someone with more AI experience to replace him
The CEO of code review platform provider Snyk has announced he will stand down so the company can find someone better-equipped to steer the company into the age of AI.…
AI agents abound, unbound by rules or safety disclosures
AI agents are becoming more common and more capable, without consensus or standards on how they should behave, say academic researchers.…
Crims create fake remote management vendor that actually sells a RAT
Researchers at Proofpoint late last month uncovered what they describe as a "weird twist" on the growing trend of criminals abusing remote monitoring and management software (RMM) as their preferred attack tools.…
Crims hit a $20M jackpot via malware-stuffed ATMs
Thieves stole more than $20 million from compromised ATMs last year using a malware-assisted technique that the FBI says is on the uptick across the United States.…
Android malware taps Gemini to navigate infected devices
Cybersecurity researchers say they've spotted the first Android malware strain that uses generative AI to improve performance once installed. But it may be only a proof of concept.…
DEF CON bans three Epstein-linked men from future events
Cybersecurity conference DEF CON has added three men named in the Epstein files to its list of banned individuals. They are not accused of any criminal wrongdoing.…
UK to demand social platforms take down abusive intimate images within 48 hours
The UK is bracketing "intimate images shared without a victim's consent" along with terror and child sexual abuse material, and demanding that online platforms remove them within two days.…
Healthcare security: Write login details on whiteboard, hope for the best
Bork!Bork!Bork! Today's bork is entirely human-generated and will send a shiver down the spine of security pros. No matter how secure a system is, a user's ability to undo an administrator's best efforts should not be underestimated.…
Poland bans camera-packing cars made in China cars from military bases
Poland’s Ministry of Defence has banned Chinese cars – and any others include tech to record position, images, or sound – from entering protected military facilities.…
Adidas investigates third-party data breach after criminals claim they pwned the sportswear giant
Adidas has confirmed it is investigating a third-party breach at one of its partner companies after digital thieves claimed they stole information and technical data from the German sportswear giant.…
ShinyHunters allegedly drove off with 1.7M CarGurus records
CarGurus allegedly suffered a data breach with 1.7 million corporate records stolen, according to a notorious cybercrime crew that posted the online vehicle marketplace on its leak site on Wednesday.…
Fraudster hacked hotel system, paid 1 cent for luxury rooms, Spanish cops say
Spanish police arrested a hacker who allegedly manipulated a hotel booking website, allowing him to pay one cent for luxury hotel stays. He also raided the mini-bars and didn't settle some of those tabs, police say.…