The Register

Subscribe to The Register feed
Biting the hand that feeds IT — Enterprise Technology News and Analysis
Updated: 5 min 22 sec ago

ShinyHunters claims Okta customer breaches, leaks data belonging to 3 orgs

Fri, 23/01/2026 - 18:46
'A lot more' victims to come, we're told

ShinyHunters has claimed responsibility for an Okta voice-phishing campaign during which the extortionist crew allegedly gained access to Crunchbase and Betterment.…

Categories: News

AI-powered cyberattack kits are 'just a matter of time,' warns Google exec

Fri, 23/01/2026 - 17:10
Security chief says criminals are already automating workflows, with full end-to-end tools likely within years

CISOs must prepare for "a really different world" where cybercriminals can reliably automate cyberattacks at scale, according to a senior Googler.…

Categories: News

Fortinet admits FortiGate SSO bug still exploitable despite December patch

Fri, 23/01/2026 - 12:43
Fix didn't quite do the job – attackers spotted logging in

Fortinet has confirmed that attackers are actively bypassing a December patch for a critical FortiCloud single sign-on (SSO) authentication flaw after customers reported suspicious logins on devices supposedly fully up to date.…

Categories: News

London boroughs limping back online months after cyberattack

Fri, 23/01/2026 - 10:34
Direct debits? Maybe February. Birth certificates? Dream on. Council tax bills? Oh, those are coming

Hammersmith & Fulham Council says payments are now being processed as usual, two months after a cyberattack that affected multiple boroughs in the UK's capital city.…

Categories: News

Marching orders delayed: Veterans' Digital ID off to a slow start

Fri, 23/01/2026 - 09:28
Much owed to the few, but takeup is under 1%

More than 15,000 former members of the UK's armed forces have successfully applied for a digital version of their veterans ID card since its launch in October, according to the Government Digital Service (GDS). …

Categories: News

Crims hit the easy button for Scattered-Spider style helpdesk scams

Thu, 22/01/2026 - 23:08
Teach a crook to phish…

Criminals can more easily pull off social engineering scams and other forms of identity fraud thanks to custom voice-phishing kits being sold on dark web forums and messaging platforms.…

Categories: News

Crims compromised energy firms' Microsoft accounts, sent 600 phishing emails

Thu, 22/01/2026 - 19:18
Logging in, not breaking in

Unknown attackers are abusing Microsoft SharePoint file-sharing services to target multiple energy-sector organizations, harvest user credentials, take over corporate inboxes, and then send hundreds of phishing emails from compromised accounts to contacts inside and outside those organizations.…

Categories: News

FortiGate firewalls hit by silent SSO intrusions and config theft

Thu, 22/01/2026 - 16:07
Admins say attackers are still getting in despite recent patches

FortiGate firewalls are getting quietly reconfigured and stripped down by miscreants who've figured out how to sidestep SSO protections and grab sensitive settings right out of the box.…

Categories: News

Europe's GDPR cops dished out €1.2B in fines last year as data breaches piled up

Thu, 22/01/2026 - 13:39
Regulators logged over 400 personal data breach notifications a day for first time since law came into force

GDPR fines pushed past the £1 billion (€1.2 billion) mark in 2025 as Europe's regulators were deluged with more than 400 data breach notifications a day, according to a new survey that suggests the post-plateau era of enforcement has well and truly arrived.…

Categories: News

Bank of England: Financial sector failing to implement basic cybersecurity controls

Thu, 22/01/2026 - 13:23
Mind the cyber gap – similar flaws highlighted multiple years in a row

Concerned about the orgs that safeguard your money? The UK's annual cybersecurity review for 2025 suggests you should be. Despite years of regulation, financial organizations continue to miss basic cybersecurity safeguards.…

Categories: News

Ancient telnet bug happily hands out root to attackers

Thu, 22/01/2026 - 12:13
Critical vuln flew under the radar for a decade

A recently disclosed critical vulnerability in the GNU InetUtils telnet daemon (telnetd) is "trivial" to exploit, experts say.…

Categories: News

Another week, another emergency patch as Cisco plugs Unified Comms zero-day

Thu, 22/01/2026 - 10:54
The critical-rated flaw leaves unpatched systems open to full takeover

Cisco has finally shipped a fix for a critical-rated zero-day in its Unified Communications gear, a flaw that's already being weaponized in the wild, and which CISA previously flagged as an emergency priority.…

Categories: News

Davos discussion mulls how to keep AI agents from running wild

Wed, 21/01/2026 - 23:04
Where the shiny new FOMO object collides with insider-threat reality

AI agents arrived in Davos this week with the question of how to secure them - and prevent agents from becoming the ultimate insider threat - taking center stage during a panel discussion on cyber threats.…

Categories: News

Don't click on the LastPass 'create backup' link - it's a scam

Wed, 21/01/2026 - 18:10
Phishing campaign tries to reel in master passwords

Password managers make great targets for attackers because they can hold many of the keys to your kingdom. Now, LastPass has warned customers about phishing emails claiming that action is required ahead of scheduled maintenance and told them not to fall for the scam. …

Categories: News

Everest ransomware gang said to be sitting on mountain of Under Armour data

Wed, 21/01/2026 - 15:29
Have I Been Pwned reckons 72.7M customer accounts affected, sportswear firm remains silent

Have I Been Pwned (HIBP) says 72.7 million accounts registered with Under Armour were affected by an alleged ransomware attack in November.…

Categories: News

EU considers whether there's Huawei of axing Chinese kit from networks within 3 years

Wed, 21/01/2026 - 13:42
Still dominant in Germany's networks, among others

The European Commission (EC) wants a revised Cybersecurity Act to address any threats posed by IT and telecoms kit from third-country sources, potentially forcing member states to confront the thorny issue of suppliers such Huawei in their national networks.…

Categories: News

Ireland wants to give its cops spyware, ability to crack encrypted messages

Wed, 21/01/2026 - 13:05
Its very own Snooper’s Charter comes a month after proposed biometric tech expansion

The Irish government is planning to bolster its police's ability to intercept communications, including encrypted messages, and provide a legal basis for spyware use.…

Categories: News

Best of British: UK's infosec envoys include Cisco, Palo Alto, and Accenture

Wed, 21/01/2026 - 12:31
Minister unwraps ambassadors of the Software Security Code of Practice

Britain's digital economy minister has sent forth a raft of companies as "ambassadors" to help organizations across the land embrace the UK's Software Security Code of Practice.…

Categories: News

Curl shutters bug bounty program to remove incentive for submitting AI slop

Wed, 21/01/2026 - 05:29
Maintainer hopes hackers send bug reports anyway, will keep shaming ‘silly' ones

The maintainer of popular open-source data transfer tool cURL has ended the project’s bug bounty program after maintainers struggled to assess a flood of AI-generated contributions.…

Categories: News

Cloudflare whacks WAF bypass bug that opened side door for attackers

Tue, 20/01/2026 - 23:05
ACME validation had a challenge-request hole

Cloudflare has fixed a flaw in its web application firewall (WAF) that allowed attackers to bypass security rules and directly access origin servers, which could lead to data theft or full server takeover.…

Categories: News

Pages