The Register
Credential-stealing crew spoofs VPN clients from Cisco, Fortinet, and others
A group of cybercriminals tracked as Storm-2561 is using fake enterprise VPN clients from CheckPoint, Cisco, Fortinet, Ivanti, and other vendors to steal users' credentials, according to Microsoft.…
Interpol cybercrime crackdown leads to 94 arrests, 45,000 IP takedowns
Ninety-four people were arrested as part of a global, multi-month cybercrime crackdown, Interpol revealed today.…
NanoClaw latches onto Docker Sandboxes for safer AI agents
exclusive NanoClaw, an open source agent platform, can now run inside Docker Sandboxes, furthering the project's commitment to security.…
Google rushes Chrome update fixing two zero-days already under attack
Google has pushed out an emergency Chrome update to fix two previously unknown vulnerabilities that attackers were already exploiting before the patches landed.…
Rogue AI agents can work together to hack systems and steal secrets
AI agents work together to bypass security controls and stealthily steal sensitive data from within the enterprise systems in which they operate, according to tests carried out by frontier security lab Irregular.…
Operating Lightning takes down SocksEscort proxy network blamed for tens of millions in fraud
Cops from eight countries this week disrupted SocksEscort, a residential proxy service used by criminals to compromise hundreds of thousands of routers worldwide and carry out digital fraud, costing businesses and consumers millions.…
CISA warns max-severity n8n bug is being exploited in the wild
The US Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that hackers are exploiting a max-severity remote code execution (RCE) vulnerability in workflow automation platform n8n.…
China’s CERT warns OpenClaw can inflict nasty wounds
China’s National Computer Network Emergency Response Technical Team has warned locals that the OpenClaw agentic AI tool poses significant security risks.…
Iran plots 'infrastructure warfare' against US tech giants
Iran has reportedly designated Amazon, Google, IBM, Microsoft, Nvidia, Oracle, and Palantir facilities as legitimate targets of retaliatory strikes, according to an Al Jazeera report citing Iran’s state-affiliated Tasnim news agency.…
Iran-linked cyber crew says they hit US med-tech firm
A hacking crew with ties to Iran's intelligence agency claimed to be behind a global network outage at med-tech firm Stryker on Wednesday, and said the cyberattack was in response to the US-Israel airstrikes.…
Meta, international cops use handcuffs and AI to stop scammers
Not every scam starts with malware or a compromised account. Sometimes all it takes is a friend request or a link shared via chat.…
ICO fines Police Scotland over data-sharing debacle in gross misconduct case
The UK's data protection watchdog has fined Police Scotland £66,000 ($88,000) for what it calls a "serious failure" in handling an alleged victim's sensitive data.…
Swiss e-voting pilot can't count 2,048 ballots after USB keys fail to decrypt them
A Swiss canton has suspended its pilot of electronic voting after failing to count 2,048 votes cast in national referendums held on March 8.…
Dutch cops bust teen suspected of posing as bank staff to steal cards
Dutch police have arrested a 17-year-old boy who detectives suspect was responsible for 16 bank card frauds across the Netherlands.…
EU legal eagle says banks should refund cybercrime victims first, argue later
Analysis One of the European Union's top legal advisors is trying to change how banks treat cybercrime victims – meaning they could enjoy greater financial protections sooner than expected.…
Building the UK’s next generation of cyber talent
Partner Content The UK Cyber Team is a government initiative led by the Department for Science, Innovation and Technology in partnership with SANS Institute. Its purpose is to identify, develop, and support the UK’s most promising emerging cyber talent, while ensuring the UK is represented with confidence and credibility on the international cyber stage.…
Critical Microsoft Excel bug weaponizes Copilot Agent for zero-click information disclosure attack
After a whopper of a Patch Tuesday last month, with six Microsoft flaws exploited as zero-days, March didn't exactly roar in like a lion. Just two of the 83 Microsoft CVEs released on Tuesday are listed as publicly known, and none is under active exploitation, which we're sure is a welcome change to sysadmins.…
Cybercrime isn't just a cover for Iran's government goons - it's a key part of their operations
Iranian government-backed snoops are increasingly using cybercrime malware and ransomware infrastructure in their operations - not just hiding behind criminal masks as a cover for destructive cyber activity, according to security researchers.…
Crooks compromise WordPress sites to push infostealers via fake CAPTCHA prompts
Cyber baddies quietly compromised legitimate WordPress websites, including the campaign site of a US Senate candidate, turning them into launchpads for a global infostealer operation.…
Fake job applications pack malware that kills EDR before stealing data
A Russian-speaking cyber criminal is targeting corporate HR teams with fake CVs that quietly install malware which can disable security tools before stealing data from infected machines.…