The Register
Ex-Disney employee gets 3 years in the clink for goofy attacks on mousey menus
Former Disney employee Michael Scheuer was sentenced to 36 months in prison and fined almost $688,000 for screwing up a software application the entertainment giant used to cook up its restaurant menus.…
Cybersecurity CEO accused of running malware on hospital PC blabs about it on LinkedIn
An Oklahoma City cybersecurity professional accused of installing spyware on a hospital PC confirmed on LinkedIn key details of the drama.…
How to survive as a CISO aka 'chief scapegoat officer'
RSAC Chief security officers should negotiate personal liability insurance and a golden parachute when they start a new job – in case things go sideways and management tries to scapegoat them for a network breach.…
Admission impossible: NSA, CISA brass absent from RSA Conf
RSAC There's a notable absence from this year's RSA Conference that kicked off today in San Francisco: The NSA's State of the Hack panel.…
The future of AI in cybersecurity in a word: Optimistic
Sponsored post AI is reshaping cybersecurity in real time, raising the stakes on both sides of the battlefield. For defenders, it brings speed, precision, and automation at scale, helping security teams detect threats earlier and respond faster than ever. But adversaries aren’t standing still. They’re using AI to sharpen their own tactics, accelerating attacks and probing defenses with unprecedented sophistication.…
From 112k to 4 million folks' data – HR biz attack goes from bad to mega bad
Houston-based VeriSource Services' long-running probe into a February 2024 digital break-in shows the data of 4 million people – not just a few hundred thousand as it first claimed - was accessed by an "unknown actor".…
Back online after 'catastrophic' attack, 4chan says it's too broke for good IT
Clearweb cesspit 4chan is back up and running, but says the damage caused by a cyberattack earlier this month was "catastrophic."…
Microsoft pitches pay-to-patch reboot reduction subscription for Windows Server 2025
Microsoft has announced that its preview of hotpatching for on-prem Windows Server 2025 will become a paid subscription service in July.…
Samsung admits Galaxy devices can leak passwords through clipboard wormhole
Infosec in brief Samsung has warned that some of its Galaxy devices store passwords in plaintext.…
Signalgate lessons learned: If creating a culture of security is the goal, America is screwed
Opinion Just when it seems they couldn't be that careless, US officials tasked with defending the nation go and do something else that puts American critical infrastructure, national security, and troops' lives in danger.…
Amid CVE funding fumble, 'we were mushrooms, kept in the dark,' says board member
Kent Landfield, a founding member of the Common Vulnerabilities and Exposures (CVE) program and member of the board, learned through social media that the system he helped create was just hours away from losing funding.…
More Ivanti attacks may be on horizon, say experts who are seeing 9x surge in endpoint scans
Ivanti VPN users should stay alert as IP scanning for the vendor's Connect Secure and Pulse Secure systems surged by 800 percent last week, according to threat intel biz GreyNoise.…
Oh, cool. Microsoft melts bug that froze Server 2025 Remote Desktop sessions
More than one month after complaints starting flying, Microsoft has fixed a Windows bug that caused some Remote Desktop sessions to freeze.…
M&S stops online orders as 'cyber incident' issues worsen
Marks & Spencer has paused online orders for customers via its website and app as the UK retailer continues to wrestle with an ongoing "cyber incident."…
Emergency patch for potential SAP zero-day that could grant full system control
SAP's latest out-of-band patch is for a perfect 10/10 bug in NetWeaver that experts suspect could have already been exploited as a zero-day.…
Claims assistance firm fined for cold-calling people who put themselves on opt-out list
Britain's data privacy watchdog has slapped a fine of £90k ($120k) on a business that targeted people with intrusive marketing phone calls, despite them being registered with the official "Do Not Call" opt-out service.…
Darcula adds AI to its DIY phishing kits to help would-be vampires bleed victims dry
Darcula, a cybercrime outfit that offers a phishing-as-a-service kit to other criminals, this week added AI capabilities to its kit that help would-be vampires spin up phishing sites in multiple languages more efficiently.…
SSNs and more on 5.5M+ patients feared stolen from Yale Health
Yale New Haven Health has notified more than 5.5 million people that their private details were likely stolen by miscreants who broke into the healthcare system's network last month.…
Microsoft mystery folder fix might need a fix of its own
Turns out Microsoft's latest patch job might need a patch of its own, again. This time, the culprit is a mysterious inetpub folder quietly deployed by Redmond, now hijacked by a security researcher to break Windows updates.…
Assassin's Creed maker faces GDPR complaint for forcing single-player gamers online
For anyone who's ever been frustrated by the need to go online to play a single-player video game, the European privacy specialists at noyb have heard you, and they've filed a complaint against Ubisoft in Austria dealing specifically with the issue. …