The Register

Subscribe to The Register feed
Biting the hand that feeds IT — Enterprise Technology News and Analysis
Updated: 1 hour 15 min ago

Commvault fixes critical Command Center issue after flaw finder alert

Tue, 13/05/2025 - 18:31
Pay-to-play security on CVSS 10 issue is now fixed

An update that fixed a critical flaw in data protection biz Commvault's Command Center was initially not available to a significant user subset – those testing out a free trial version of the product. That is, until a security researcher pointed out the problem.…

Categories: News

'We still have embeds in CISA': CTO of Brit cyber agency talks post-Trump relationship with US counterpart

Tue, 13/05/2025 - 15:00
Both agencies seem unbothered despite tech world's clear concerns for US infoseccers

CYBERUK  The top brass from the UK's cyber agency say everything is business as usual when it comes to the GCHQ arm's relationship with CISA, amid growing unease about the current administration's treatment of its US equivalent.…

Categories: News

Marks & Spencer admits cybercrooks made off with customer info

Tue, 13/05/2025 - 11:45
Market cap down by more than £1B since April 22

Marks & Spencer has confirmed that customer data was stolen as part of its cyberattack, fueling conjecture that ransomware was involved.…

Categories: News

As US vuln-tracking falters, EU enters with its own security bug database

Tue, 13/05/2025 - 11:00
EUVD comes into play not a moment too soon

The European Vulnerability Database (EUVD) is now fully operational, offering a streamlined platform to monitor critical and actively exploited security flaws amid the US struggles with budget cuts, delayed disclosures, and confusion around the future of its own tracking systems.…

Categories: News

Türkiye-linked spy crew exploited a messaging app zero-day to snoop on Kurdish army in Iraq

Tue, 13/05/2025 - 08:29
'MarbledDust' gang has honed the skills it uses to assist Ankara

Turkish spies exploited a zero-day bug in a messaging app to collect info on the Kurdish army in Iraq, according to Microsoft, which says the attacks began more than a year ago.…

Categories: News

M365 apps on Windows 10 to get security fixes into 2028

Mon, 12/05/2025 - 23:03
Support for the underlying OS is another story

Microsoft has pledged to support and issue security fixes for M365 apps on Windows 10 into late 2028. That's well past a cut-off point of October 14 this year, when Redmond's support for Windows 10 officially ends unless you buy an extended support package.…

Categories: News

CISA mutes own website, shifts routine cyber alerts to Musk’s X, RSS, email

Mon, 12/05/2025 - 20:04
Cripes, we were only joking when we called Elon's social network the new state media

The US government's Cybersecurity and Infrastructure Security Agency (CISA) announced Monday that going forward, only urgent alerts tied to emerging threats or major cyber activity will appear on its website. Routine updates, guidance, and other notifications will instead be shared via email, RSS, and X.…

Categories: News

Why aggregating your asset inventory leads to better security

Mon, 12/05/2025 - 19:42
Today’s complex IT environments demand a new approach

Partner content  For many organizations, managing IT assets is like trying to complete a jigsaw puzzle without all the pieces. Despite massive investments in security tools and controls, many companies still have critical gaps in their ecosystems that leave them vulnerable to breaches.…

Categories: News

Attackers pwn charter airline helping Trump's deportation campaign

Mon, 12/05/2025 - 18:03
Intruders claim they stole GlobalX's flight records and manifests

GlobalX, a charter airline used for deportations by the US government, has admitted someone broke into its network infrastructure.…

Categories: News

Britain's cyber agents and industry clash over how to tackle shoddy software

Mon, 12/05/2025 - 10:33
Providers argue that if end users prioritized security, they'd get it

CYBERUK  Intervention is required to ensure the security market holds vendors to account for shipping insecure wares – imposing costs on those whose failures lead to cyberattacks and having to draft in cleanup crews. The security market must properly incentivize security vendors to do security better.…

Categories: News

Unending ransomware attacks are a symptom, not the sickness

Mon, 12/05/2025 - 09:30
We need to make taking IT systems 'off the books' a problem for corporate types

Opinion  It's been a devastating few weeks for UK retail giants. Marks and Spencer, the Co-Op, and now uber-posh Harrods have had massive disruptions due to ransomware attacks taking systems down for prolonged periods.…

Categories: News

DOGE worker's old creds found exposed in infostealer malware dumps

Mon, 12/05/2025 - 05:30
PLUS: Celsius scammer sent to slammer; Death-by-hacking victim warns you're never safe; and more

Infosec in brief  Good cybersecurity habits don't appear to qualify anyone to work at DOGE, as one Musk minion seemingly fell victim to infostealer malware.…

Categories: News

You think ransomware is bad now? Wait until it infects CPUs

Sun, 11/05/2025 - 21:22
Rapid7 threat hunter told The Reg wrote a PoC. No he's not releasing it

RSAC  If Rapid7's Christiaan Beek decided to change careers and become a ransomware criminal, he knows exactly how he'd innovate: CPU ransomware.…

Categories: News

Pages