15 Jun

PRC-linked spies hid inside medical and military networks for more than a year, snooping through Gmail and stealing data

RESEARCH Google says the intruders were on the hunt for everything from drone tech to pathogens Chinese government spies remained hidden in the networks of

Author rabih
15 Jun

Arch Linux locks down AUR signups amid wave of malicious commits

Security Community repo freezes new accounts after attackers swamp it with poisoned package updates A wave of malicious commits hit the Arch User Repository (AUR)

Author rabih
15 Jun

EvilTokens: A phishing attack that doesn’t steal your password

Cybercrime A phishing kit subverting Microsoft’s legitimate authentication flow lets attackers break into accounts without stealing passwords or creating fake login pages Christian Ali Bravo

Author rabih
14 Jun

AI is code – and can’t be prompted into being smarter

The author of Java property-testing tool jqwik did not want AI coding agents using his project. So he told them not to. Then he went

Author rabih
12 Jun

NanoClaw now armed with JFrog for safer packages

ai and ml AI agents can’t be trusted, so don’t give them dangerous powers NanoClaw, a secure agent framework, has partnered with supply chain platform

Author rabih
12 Jun

Fired IT worker jailed for 21 months after sabotaging old school district

A disgruntled IT worker faces 21 months behind bars after being found guilty of sabotaging his former employer’s systems for more than a year and

Author rabih
12 Jun

Novo Nordisk reports cyberattack as UK gives Wegovy pill the nod

Security Clinical trial participant data stolen, but pharma giant says exposed records were pseudonymized Pharmaceutical giant Novo Nordisk says data related to clinical trial participants

Author rabih
12 Jun

Microsoft has mostly repaired a flaw in Surface hardware that allowed unprotected devices to be bricked by a single packet

EXCLUSIVE For the past 90 days, Microsoft has been quietly patching a firmware flaw in Surface devices that allowed the hardware to be bricked with

Author rabih
12 Jun

Google fires sueball at alleged Chinese phishers over AI-powered fraud ops

security Telegram-based ‘Outsider Enterprise’ accused of sending millions of scam texts and impersonating trusted brands Google has sued an alleged China-based cybercrime operation it says

Author rabih
12 Jun

Plymouth council exposes hundreds in latest local government email gaffe

security Authority admits mass message to home-schooling families revealed recipients’ addresses, prompting ICO report and apology Plymouth City Council has joined the growing ranks of

Author rabih
12 Jun

UK digital ID gets brain trust to ‘challenge’ ministers on policy

PUBLIC SECTOR CEO of Mumsnet among the six-member team The UK government has set up an advisory board for its digital ID project, intended “to challenge

Author rabih
12 Jun

BOFH: For one ambitious security type, chaos is a ladder

EPISODE 11 “And uh… what are you doing?” the Head of Security asks, entering the Security office as I’m making my way to the exit –

Author rabih
11 Jun

ShinyHunters claims it hacked 100 orgs by exploiting an Oracle PeopleSoft 0-day

Security University of Nottingham is first of many, Shiny tells The Reg Data theft and extortion group ShinyHunters claims to have exploited a critical Oracle

Author rabih
11 Jun

Microsoft’s worst ‘Nightmare’ unleashes BitLocker bypass 0-day

Security Another day, another Windows exploit code Nightmare Eclipse, the prolific zero-day vulnerability hunter with an axe to grind against Microsoft, released yet another exploit

Author rabih
11 Jun

2.4M+ VRChat users’ data accessed following cloud breach

security No disclosure via official channels, no offer of identity theft monitoring, no problem Online chat platform VRChat says a recent cyberattack compromised the data

Author rabih
11 Jun

OceanLotus: From external espionage to domestic targeting

Our tracking of OceanLotus activities from 2024–2026 reveals a shift in operational focus. During this period, the Vietnam-aligned OceanLotus adopted a more selective approach to

Author rabih
11 Jun

OceanLotus: From external espionage to domestic targeting

Our tracking of OceanLotus activities from 2024–2026 reveals a shift in operational focus. During this period, the Vietnam-aligned OceanLotus adopted a more selective approach to

Author rabih
11 Jun

Every employee’s password was stored in a single Excel file

SECURITY The CEO thought this was the best way to deal with some email issues PWNED Welcome, once again, to PWNED, the weekly screed where

Author rabih
Load moreLoadingAll items loaded