The Register

Subscribe to The Register feed
Biting the hand that feeds IT — Enterprise Technology News and Analysis
Updated: 1 hour 46 min ago

Star leaky app of the week: StarDict

Fri, 08/08/2025 - 16:29
Fun feature found in Debian 13: send your selected text to China – in plaintext

As Trixie gets ready to début, a little-known app is hogging the limelight: StarDict, which sends whatever text you select, unencrypted, to servers in China.…

Categories: News

Ex-White House cyber, counter-terrorism guru: Microsoft considers security an annoyance, not a necessity

Fri, 08/08/2025 - 14:00
Tells The Reg China's ability to p0wn Redmond's wares 'gives me a political aneurysm'

Comment  Roger Cressey served two US presidents as a senior cybersecurity and counter-terrorism advisor and currently worries he'll experience a "political aneurysm" due to Microsoft's many security messes.…

Categories: News

Infosec hounds spot prompt injection vuln in Google Gemini apps

Fri, 08/08/2025 - 12:30
Not a very smart home: crims could hijack smart-home boiler, open and close powered windows and more. Now fixed

Black hat  A trio of researchers has disclosed a major prompt injection vulnerability in Google's Gemini large language model-powered applications.…

Categories: News

UK secretly allows facial recognition scans of passport, immigration databases

Fri, 08/08/2025 - 11:45
Campaigners brand Home Office’s lack of transparency as ‘astonishing’ and ‘dangerous’

Privacy groups report a surge in UK police facial recognition scans of databases secretly stocked with passport photos lacking parliamentary oversight.…

Categories: News

UK proxy traffic surges as users consider VPN alternatives amid Online Safety Act

Fri, 08/08/2025 - 10:45
It's 'more than a temporary trend,' Decodo claims

Amid the furor around surging VPN usage in the UK, many users are eyeing proxies as a potential alternative to the technology.…

Categories: News

Prohibition never works, but that didn't stop the UK's Online Safety Act

Fri, 08/08/2025 - 07:45
Will someone think of the deals politicians are making?

Opinion  You might think, since I write about tech all the time, my degrees are in computer science. Nope. I'm a bona fide, degreed historian, which is why I can say with confidence that the UK's recently passed Online Safety Act is doomed to fail.…

Categories: News

Why blow up satellites when you can just hack them?

Fri, 08/08/2025 - 00:20
A pair of German researchers showed how easy it is

Black Hat  Four countries have now tested anti-satellite missiles (the US, China, Russia, and India), but it's much easier and cheaper just to hack them.…

Categories: News

German security researchers say 'Windows Hell No' to Microsoft biometrics for biz

Thu, 07/08/2025 - 21:20
Hello loophole could let a rogue admin, or a pwned one, inject new facial scans

Black Hat  Microsoft is pushing hard for Windows users to shift from using passwords to its Hello biometrics system, but researchers sponsored by the German government have found a critical flaw in its business implementation.…

Categories: News

Microsoft, CISA warn yet another Exchange server bug can lead to 'total domain compromise'

Thu, 07/08/2025 - 18:53
No reported in-the-wild exploits…yet

Microsoft and the feds late Wednesday sounded the alarm on another high-severity bug in Exchange Server hybrid deployments that could allow attackers to escalate privileges from on-premises Exchange to the cloud.…

Categories: News

Black Hat's network ops center brings rivals together for a common cause

Thu, 07/08/2025 - 16:00
The Reg goes behind the scenes of the conference NOC, where volunteers 'look for a needle in a needle stack'

Black Hat  Neil "Grifter" Wyler is spending the week "looking for a needle in a needle stack," a task he'll perform from the network operations center (NOC) that powers the Black Hat security conference in Las Vegas.…

Categories: News

CISA releases malware analysis for Sharepoint Server attack

Thu, 07/08/2025 - 15:30
Indications of compromise and Sigma rules report for your security scanners amid ongoing 'ToolShell' blitz

CISA has published a malware analysis report with compromise indicators and Sigma rules for "ToolShell" attacks targeting specific Microsoft SharePoint Server versions.…

Categories: News

KLM, Air France latest major organizations looted for customer data

Thu, 07/08/2025 - 14:00
Watch out, the phishermen are about, customers told

European airline giants Air France and KLM say they are the latest in a string of major organizations to have their customers' data stolen by way of a break-in at a third party org.…

Categories: News

Meta training AI on social media posts? Only 7% in Europe think it's OK

Thu, 07/08/2025 - 13:30
Privacy campaigner Max Schrem's NOYB is back on Zuck's back

Meta's enthusiasm for training its AI on user data is not shared by the users themselves – at least for some Europeans – according a study commissioned by Facebook legal nemesis Max Schrems and his privacy advocacy group Noyb.…

Categories: News

Amnesty slams Elon Musk's X for 'central role' in fueling 2024 UK riots

Thu, 07/08/2025 - 09:45
Human rights org calls for greater accountability and stronger enforcement of Online Safety Act

Amnesty International claims Elon Musk's X platform "played a central role" in pushing the misinformation that stoked racially charged violence following last year's Southport murders.…

Categories: News

Could agentic AI save us from the cybercrisis?

Thu, 07/08/2025 - 09:00
Many hands make light work in the SOC

Sponsored feature  The cyberthreat landscape is evolving fast, with highly organized bad actors launching ever more devastating and sophisticated attacks against often ill-prepared targets.…

Categories: News

Microsoft researchers bullish on AI security agent even though it let 74% of malware slip through

Wed, 06/08/2025 - 22:00
Project Ire promises to use LLMs to detect whether code is malicious or benign

Microsoft has rolled out an autonomous AI agent that it claims can detect malware without human assistance.…

Categories: News

Google says the group behind last year's Snowflake attack slurped data from one of its Salesforce instances

Wed, 06/08/2025 - 19:00
ShinyHunters suspected in rash of intrusions

Google confirmed that criminals breached one of its Salesforce databases and stole info belonging to some of its small-and-medium-business customers.…

Categories: News

Vibe coding tool Cursor's MCP implementation allows persistent code execution

Wed, 06/08/2025 - 00:28
More evidence that AI expands the attack surface

Check Point researchers uncovered a remote code execution bug in popular vibe-coding AI tool Cursor that could allow an attacker to poison developer environments by secretly modifying a previously approved Model Context Protocol (MCP) configuration, silently swapping it for a malicious command without any user prompt.…

Categories: News

Patch now: Millions of Dell PCs with Broadcom chips vulnerable to attack

Tue, 05/08/2025 - 19:28
Psst, wanna steal someone's biometrics?

black hat  Critical security flaws in Broadcom chips used in more than 100 models of Dell computers could allow attackers to take over tens of millions of users' devices, steal passwords, and access sensitive data, including fingerprint information, according to Cisco Talos.…

Categories: News

Study finds humans not completely useless at malware detection

Tue, 05/08/2025 - 18:00
Some pinpointed software nasties but were suspicious of printer drivers too

Researchers from the Universities of Guelph and Waterloo have discovered exactly how users decide whether an application is legitimate or malware before installing it – and the good news is they're better than you might expect, at least when primed to expect malware.…

Categories: News

Pages