30 Mar

Telnyx joins LiteLLM in latest PyPI package poisoning tied to Trivy breach

infosec in brief The cybercrime crew linked to the Trivy supply-chain attack has struck again, this time pushing malicious Telnyx package versions to PyPI in

Author rabih
30 Mar

Citrix NetScaler bug exploited in days, may be multiple flaws in a trench coat

In-the-wild exploitation of a critical Citrix NetScaler bug has begun less than a week after disclosure, with researchers warning that attackers are already poking and

Author rabih
30 Mar

European Commission admits attackers broke into public web systems, but says little else

The European Commission has admitted that attackers broke into its public-facing web infrastructure and siphoned off data in a bare-bones disclosure that answers the what

Author rabih
30 Mar

Security contractor blew the whistle on support crew’s viral indifference

Who, Me? The week before Easter may be a short one for many in the Reg-reading world, but that won’t stop us from opening it

Author rabih
30 Mar

US foreign router ban criticized for being ‘industrial policy disguised as cybersecurity’

The United States’ ban on foreign-made SOHO routers won’t improve security, and only makes sense as “industrial policy disguised as cybersecurity,” according to Milton Mueller,

Author rabih
27 Mar

AFC Ajax drops ball as flaws let hackers play admin with tickets and bans

Dutch football giant AFC Ajax has admitted to a data breach after an attacker gained access to its internal systems, in an incident that looks

Author rabih
27 Mar

Iran war drives urgent need  to counter underwater attack drones

The UK and US are looking for technology to counter the threat posed by underwater drones to ships, harbors and other critical maritime infrastructure, and

Author rabih
27 Mar

RSAC 2026 wrap-up – Week in security with Tony Anscombe

This year, AI agents took the center stage – as a defensive capability, but more pressingly as a risk many organizations haven’t caught up with

Author rabih
27 Mar

Security boffins scoured the web and found hundreds of valid API keys

Computer security boffins have conducted an analysis of 10 million websites and found almost 2,000 API credentials strewn across 10,000 webpages. The researchers detail their

Author rabih
27 Mar

A cunning predator: How Silver Fox preys on Japanese firms this tax season

Business Security Silver Fox is back in Japan, spoofing tax and HR emails timed to the one season when no one thinks twice about opening

Author rabih
26 Mar

Brit lawmaker targeted by AI deepfake fails to get answers from US Big Tech

A member of the UK Parliament’s lower house who was the victim of a deepfake AI campaign this week had a rare chance to confront

Author rabih
26 Mar

UK wants to know if banning under-16s from social media does anything useful

The UK government will trial different levels of restrictions on social media for under-16s with the help of 300 families, alongside a public consultation that

Author rabih
26 Mar

Indian government probes CCTV espionage operation linked to Pakistan

Indian authorities have reportedly ordered an audit of the nation’s CCTV cameras, after police uncovered what they claim was a Pakistan-backed surveillance operation. This story

Author rabih
25 Mar

AI supply chain attacks don’t even require malware…just post poisoned documentation

A new service that helps coding agents stay up to date on their API calls could be dialing in a massive supply chain vulnerability. Two

Author rabih
25 Mar

Scammers have virtual smartphones on speed dial for fraud

Smartphones have fast become the basis of our digital identities, securing payment systems and bank accounts. Now virtual devices that pretend to be real handsets

Author rabih
25 Mar

Jen Easterly, cybersecurity’s ‘relentless optimist,’ hopes feds come back to RSAC next year

RSAC 2026 “Everybody feels massive FOMO if they don’t get to RSAC,” Jen Easterly says. To be fair, she has a vested interest in saying

Author rabih
25 Mar

Only Trump can decide when cyberwar turns into real war

rsac 2026 There’s a theoretical red line with cyber warfare. Cross it, and the US will respond with a physical attack like missile strikes. And

Author rabih
25 Mar

Virtual machines, virtually everywhere – and with real security gaps

Twenty years ago, almost to the day, Amazon Web Services (AWS) launched Simple Storage Service (S3). A few months later, the company’s Elastic Compute Cloud (EC2) service opened for public

Author rabih
Load moreLoadingAll items loaded