The Register

Subscribe to The Register feed
Biting the hand that feeds IT — Enterprise Technology News and Analysis
Updated: 7 min 8 sec ago

M&S takes systems offline as 'cyber incident' lingers

Thu, 24/04/2025 - 11:18
Customers told to expect further delays as contactless payments still down

UK high street retailer Marks & Spencer says contactless payments are still down following its "cyber incident" and order delays are likely to continue.…

Categories: News

Your vendor may be the weakest link: Percentage of third-party breaches doubled in a year

Thu, 24/04/2025 - 10:28
Cybercriminals are targeting software shops, accountants, lawyers

The percentage of confirmed data breaches involving third-party relationships doubled last year as cybercriminals increasingly exploited weak links in supply chains and partner ecosystems.…

Categories: News

Booby-trapped Alpine Quest Android app geolocates Russian soldiers

Thu, 24/04/2025 - 08:24
Back of the nyet!

Russian soldiers are being targeted with an Android app specially altered to pinpoint their location and scan their phones for files, with the ability to exfiltrate sensitive documents if instructed.…

Categories: News

Ransomware scum and other crims bilked victims out of a 'staggering' $16.6B last year, says FBI

Thu, 24/04/2025 - 01:51
Biggest threat to America's critical infrastructure? Ransomware

Digital scammers and extortionists bilked businesses and individuals in the US out of a "staggering" $16.6 billion last year, according to the FBI — the highest losses recorded since bureau’s Internet Crime Complaint Center (IC3) started tracking them 25 years ago.…

Categories: News

Blue Shield says it shared health info on up to 4.7M patients with Google Ads

Wed, 23/04/2025 - 23:18
Tech giants don't need smartphone mics to target adverts – your insurer just gives your data away, anyway

US health insurance giant Blue Shield of California handed sensitive health information belonging to as many as 4.7 million members to Google's advertising empire, likely without these individuals' knowledge or consent.…

Categories: News

Ripple NPM supply chain attack hunts for private keys

Wed, 23/04/2025 - 19:28
A mystery thief and a critical CVE involved in crypto cash grab

Many versions of the Ripple ledger (XRPL) official NPM package are compromised with malware injected to steal cryptocurrency.…

Categories: News

We’re calling it now: Agentic AI will win RSAC buzzword Bingo

Wed, 23/04/2025 - 18:41
All aboard the hype train

The security industry loves its buzzwords, and this is always on full display at the annual RSA Conference event in San Francisco. Don't believe us? Take a lap on the expo floor, and you'll be bombarded with enough acronyms and over-the-top claims to send you straight to the nearest bar, which will likely serve specialty cocktails with names like The Great CASB and Firewall Fizz.…

Categories: News

Who needs phishing when your login's already in the wild?

Wed, 23/04/2025 - 14:00
Stolen credentials edge out email tricks for cloud break-ins because they're so easy to get

Criminals used stolen credentials more frequently than email phishing to gain access into their victims' IT systems last year, marking the first time that compromised login details claimed the number two spot in Mandiant's list of most common initial infection vectors.…

Categories: News

Ex-NSA chief warns AI devs: Don’t repeat infosec’s early-day screwups

Wed, 23/04/2025 - 11:34
Bake in security now or pay later, says Mike Rogers

AI engineers should take a lesson from the early days of cybersecurity and bake safety and security into their models during development, rather than trying to bolt it on after the fact, according to former NSA boss Mike Rogers.…

Categories: News

America's cyber defenses are being dismantled from the inside

Wed, 23/04/2025 - 09:27
The CVE system nearly dying shows that someone has lost the plot

Opinion  We almost lost the Common Vulnerabilities and Exposures (CVE) database system, but that's only the tip of the iceberg of what President Trump and company are doing to US cybersecurity efforts.…

Categories: News

RIP, Google Privacy Sandbox

Tue, 22/04/2025 - 21:20
Chrome will keep third-party cookies, a win for web giant's ad rivals

After six years of work, Google's Privacy Sandbox, technology for delivering ads while protecting privacy, looks like dust in the wind.…

Categories: News

Two CISA officials jump ship, both proud of pushing for Secure by Design software

Tue, 22/04/2025 - 20:30
As cyber-agency faces cuts, makes noises about switching up program

Two top officials have resigned from Uncle Sam's Cybersecurity and Infrastructure Security Agency, aka CISA, furthering fears of a brain drain amid White House cuts to the federal workforce.…

Categories: News

Fog ransomware channels Musk with demands for work recaps or a trillion bucks

Tue, 22/04/2025 - 19:02
In effect: 'Ha ha – the government is borked and so are you'

Ransomware scumbags - potentially those behind the Fog gang - are channeling their inner Elon Musk with their latest ransom note, spotted by researchers at Trend Micro.…

Categories: News

A pot of $250K is now available to ransomware researchers, but it feeds a commercial product

Tue, 22/04/2025 - 18:08
Security bods can earn up to $10K per report

Ransomware threat hunters can now collect rewards of $10,000 for each piece of intel they file under a new bug bounty that aims to squash extortionists.…

Categories: News

This is not just any 'cyber incident' … this is an M&S 'cyber incident'

Tue, 22/04/2025 - 17:07
Retailer tight-lipped on details as digital hiccup disrupts customer orders

UK high street mainstay Marks & Spencer told the London Stock Exchange this afternoon it has been managing a "cyber incident" for "the past few days."…

Categories: News

UN says Asian scam call center epidemic expanding globally amid political heat

Tue, 22/04/2025 - 16:15
What used to be a serious issue mainly in Southeast Asia is now the world’s problem

Scam call centers are metastasizing worldwide "like a cancer," according to the United Nations, which warns the epidemic has reached a global inflection point as syndicates scale up and spread out.…

Categories: News

Bug hunter tricked SSL.com into issuing cert for Alibaba Cloud domain in 5 steps

Tue, 22/04/2025 - 03:23
10 other certificates 'were mis-issued and have now been revoked'

Certificate issuer SSL.com’s domain validation system had an unfortunate bug that was exploited by miscreants to obtain, without authorization, digital certs for legit websites.…

Categories: News

Today's LLMs craft exploits from patches at lightning speed

Mon, 21/04/2025 - 21:31
Erlang? Er, man, no problem. ChatGPT, Claude to go from flaw disclosure to actual attack code in hours

The time from vulnerability disclosure to proof-of-concept (PoC) exploit code can now be as short as a few hours, thanks to generative AI models.…

Categories: News

Microsoft rated this bug as low exploitability. Miscreants weaponized it in just 8 days

Mon, 21/04/2025 - 18:43
It's now hitting govt, enterprise targets

On March 11 - Patch Tuesday - Microsoft rolled out its usual buffet of bug fixes. Just eight days later, miscreants had weaponized one of the vulnerabilities, using it against government and private sector targets in Poland and Romania.…

Categories: News

Hacking US crosswalks to talk like Zuck is as easy as 1234

Sat, 19/04/2025 - 14:03
AI-spoofed Mark joins fellow billionaires as the voice of the street – here's how it was probably done

Video  Crosswalk buttons in various US cities were hijacked over the past week or so to – rather than robotically tell people it's safe to walk or wait – instead emit the AI-spoofed voices of Jeff Bezos, Elon Musk, and Mark Zuckerberg.…

Categories: News

Pages