The Register
The story behind the Health Infrastructure Security and Accountability Act
Partner Content Breaches breed regulation; which hopefully in turn breeds meaningful change.…
Admins better Spring into action over latest critical open source vuln
If you're running an application built using the Spring development framework, now is a good time to check it's fully updated – a new, critical-severity vulnerability has just been disclosed.…
Merde! Macron's bodyguards reveal his location by sharing Strava data
The French equivalent of the US Secret Service may have been letting their guard down, as an investigation showed they are easily trackable via the fitness app Strava.…
Five Eyes nations tell tech startups to take infosec seriously. Again
Cyber security agencies from the Five Eyes nations have delivered on a promise to offer tech startups more guidance on how to stay secure.…
Wanted. Top infosec pros willing to defend Britain on shabby salaries
While the wages paid by governments seldom match those available in the private sector, it appears that the UK's intelligence, security and cyber agency is a long way short of being competitive in its quest for talent.…
JPMorgan Chase sues scammers following viral 'infinite money glitch'
JPMorgan Chase has begun suing fraudsters who allegedly stole thousands of dollars from the bank's ATMs after a check fraud glitch went viral on social media.…
Feds investigate China's Salt Typhoon amid campaign phone hacks
The feds are investigating Chinese government-linked cyberspies breaking into the infrastructure of US telecom companies, as reports suggest Salt Typhoon - the same crew believed to be behind those hacks - has also been targeting phones belonging to people affiliated with US Democratic presidential candidate Kamala Harris, along with Republican candidate Donald Trump and his running mate, JD Vance.…
Brazen crims selling stolen credit cards on Meta's Threads
Exclusive Brazen crooks are selling people's pilfered financial information on Meta's Threads, in some cases posting full credit card details, plus stolen credentials, alongside images of the cards themselves.…
Delta officially launches lawyers at $500M CrowdStrike problem
Delta Air Lines is suing CrowdStrike in a bid to recover the circa $500 million in estimated lost revenue months after the cybersecurity company "caused" an infamous global IT outage.…
Dutch cops pwn the Redline and Meta infostealers, leak 'VIP' aliases
Dutch police (Politie) say they've dismantled the servers powering the Redline and Meta infostealers – two key tools in a modern cyber crook's arsenal.…
WordPress forces user conf organizers to share social media credentials, arousing suspicions
Organisers of WordCamps, community-organized events for WordPress users, have been ordered to take down some social media posts and share their login credentials for social networks.…
Senator accuses sloppy domain registrars of aiding Russian disinfo campaigns
in brief Senate intelligence committee chair Mark Warner (D-VA) is demanding to know why, in the wake of the bust-up of a massive online Russian disinformation operation, the names of six US-based domain registrars seem to keep popping up as, at best, negligent facilitators of election meddling. …
Worker surveillance must comply with credit reporting rules
The US Consumer Financial Protection Bureau on Thursday published guidance advising businesses that third-party reports about workers must comply with the consent and transparency requirements set forth in the Fair Credit Reporting Act.…
Just how private is Apple's Private Cloud Compute? You can test it to find out
In June, Apple used its Worldwide Developer Conference to announce the creation of the Private Cloud Compute platform to run its AI Intelligence applications, and now it's asking people to stress test the system for security holes.…
Putin's pro-Trump trolls accuse Harris of poaching rhinos
Russian, Iranian, and Chinese trolls are all ramping up their US election disinformation efforts ahead of November 5, but – aside from undermining faith in the democratic process and confidence in the election result – with very different objectives, according to Microsoft.…
AWS Cloud Development Kit flaw exposed accounts to full takeover
Amazon Web Services has fixed a flaw in its open source Cloud Development Kit that, under the right conditions, could allow an attacker to hijack a user's account completely.…
Emergency patch: Cisco fixes bug under exploit in brute-force attacks
Cisco has patched an already exploited security hole in its Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) software that miscreants have been brute-forcing in attempted denial of service attacks.…
Bitwarden's FOSS halo slips as new SDK requirement locks down freedoms
The Bitwarden online credentials storage service is changing its build requirements – which some commentators feel mean it's no longer FOSS.…
Ransomware's ripple effect felt across ERs as patient care suffers
Ransomware infected 389 US healthcare organizations this fiscal year, putting patients' lives at risk and costing facilities up to $900,000 a day in downtime alone, according to Microsoft.…
Voice-enabled AI agents can automate everything, even your phone scams
Scammers, rejoice. OpenAI's real-time voice API can be used to build AI agents capable of conducting successful phone call scams for less than a dollar.…