Healthcare cyberattacks hit pacemakers and millions of patient records McKesson admits breach as ShinyHunters demands $55.2M
OpenClaw 2.0 pours glitter on slow-burning security dumpster fire Making installation easier and putting a new wrapper on the interface while leaving most of the security to users is a recipe for more trouble with the popular agent harness
Attack hides malware in PNGs and drops custom reverse tunnel on victims' machines Next-level ClickFix wave sets off multi-stage attack chain
Anthropic cracks down on hijacked user accounts mining AI tokens Commodity malware steals authenticated sessions, letting thieves freeload on victims' paid usage
Turns out Brits would quite like their private messages to stay private Polling finds two-thirds don't trust this government, or any future one, with access to their encrypted chats
Researcher shows how Claude Code can be tricked simply by asking it to summarize a website More prompt-injection hijinks from wunderwuzzi
US government snitch-finder pleads guilty to leaking state secrets to foreign spies The IT specialist began contacting a foreign government within days of being assigned to the DIA’s Insider Threat Division
CISA: Most exploited vulnerabilities should have been eradicated decades ago Organizational culture and systemic gaps in Secure by Design adoption blamed for sorry state of affairs
Industry that built the problem offers to sell you the solution 100+ tech giants warn AI attacks are coming, skip the part where they pay for defenses
Print management outfit PaperCut is under 0-day attack, and it’s drawing customers’ blood The fix is either an unvalidated and unofficial emergency patch or taking the server offline
Australian cops cuff alleged TeamPCP masterminds Alleged crew behind the Shai-Hulud worm and other supply chain attacks nabbed with help from the FBI
CRPx0 hacking service for dummies claims victim count more than quintupled It's 'built to be operated by a human with no technical background'
AI girlfriend review site's secrets were exposed to the world for three weeks Even testing and staging sites need protection from prying eyes
ATF responds to 'major' cybersecurity incident after ransomware gang's claims US Justice Department investigating the breach
Cybercrooks jet off with Manchester Airports Group customer data UK’s largest airport operator believes 8.7 million customers affected
Nuisance-call blocker fined £190k for being a nuisance caller Elderly Aids made 758,000 unwanted calls a year selling gear to stop unwanted calls
FBI seizes hacking tools it says China used to attack NASA, DOE, US Senate and other critical networks Beijing's botnets busted
OpenAI explains how its naughty AI agents attacked Hugging Face Biz describes its act of automated irresponsibility as 'a warning shot'
More than 100 water systems were hit in July cyberattacks 'These are test runs for a larger-scale attack'
Boston Scientific discloses 'global disruption' in ongoing cyberattack No timeline to restore IT systems as probe remains ongoing
Carhartt data breach affects 12.9M, half of what ShinyHunters claimed One AI and two trained eyes delved into the heavily padded leaks
You could've applied all 1,449 Oracle patches and still been hit by this attack Attackers now ready to exploit how things work, rather than just break them, says Oracle support expert
CISA slaps its tightest three-day patching deadline on perfect-10 Oracle flaw Disclosed in January and honeypots buzzed soon after, CISA says it’s finally time for the USG to plug the gap
Crooks push Mac malware through fake OpenAI Codex ads Sponsored search results lead developers straight into a ClickFix malware trap
You don't want this Sleepwalker backdoor on your Windows machine Its own command language, 23 instructions - signs point to 'well-resourced operation rather than an opportunistic one'
Browser fingerprint tool shows how easy you are to track using the latest sneaky tricks Glassbox dev admits he had some help from Claude to build locally running tool
Iran-linked cyberattack shut down a UK power plant No risk to wider energy system, government tells The Reg
ShinyHunters and ReliaQuest trade blows over claimed breach Attackers took a look at an employee's identity dashboard, but security firm says that's as far as they got
AliExpress accused of fingerprinting shoppers with silent audio trick that also muted a dev's headphones Sawtooth waves you can't hear still mess with your Bluetooth. Firefox and Brave say they've got you covered
$1T investment giant Apollo breached after social engineering attack Hackers spent four days inside the org's cloud platforms after apparently talking their way in
Security vets rally around $4 paper password books for sale in Australia Once shunned by the IT crowd, pen-and-paper password vaults are getting the love they deserve in 2026
If you're not using AI to attack your own systems, your adversaries will Agents are also the new attack surface - cue defenders' existential angst
Homeland security cybercops say patch TrueConf (Russia's Zoom) if you're using it Ukrainian hacktivists exploiting the bugs, but TrueConf's reach stretches well beyond home turf
SickKids children’s hospital bandages up careers website after intruder breaks in Toronto org says it wasn’t the only one to be affected by the third-party software vulnerability
Hackers poison popular Rust crates to steal developers' credentials Malicious updates turned routine builds into a delivery system for infostealer malware
$10K phishing kit claims it can plant rogue passkeys for persistent access to pwned accounts Seller's demos show a browser-in-the-middle attack adding credentials seconds after authentication
Microsoft sounds alarm over perfect-10 Entra ID flaw Redmond says the cloud identity bug is already fixed
Cisco bug severity warning reads like Olympic gymnastics scores: 10, 10, 9.9, 9.6, and 7.5. Secure Workload Software has five nasty flaws and even SaaS users have updates to install
Russian snoops add OAuth abuse to targeted phishing campaigns Don't click on that State Department meeting invite
Researcher tricks Apple’s Find My into sharing location data with Linux Clever protocol wrangling gets iBiz-only people tracking working on a non-iGadget
Ransomware crook poses as recovery firm to steal payments from fellow extortionists Because apparently even ransomware gangs can't trust the people they do business with
Grok chat duped into swallowing injected instructions A spoonful of encryption helps the malware go down
French tax authority says break-in exposed data of 600K, including some private messages Stolen details range from contact information to household finances and withholding rates
AI agent suggested installing a malware package. Engineer almost took its advice Fortunately, the company had a policy of checking source code on GitHub first
'Not a theoretical risk,' feds warn as attackers use AI-made code to hack critical infrastructure controllers 'It is an active threat'
ICE boss to agents: Leave the Meta spy glasses at home 'Personally owned body-worn cameras are prohibited,' ICE tells The Reg. Because the last thing DHS needs is more proof of misconduct
Flock surveillance backlash mounts as fiendish Halloween plans circulate CEO apologizes for police misuse as activists call for vandal action against license plate cameras
Comcast gives its Wi-Fi motion detector a security makeover Rebranded feature promises household alerts without video, but mind the small print
Australian hotel chain leaks guests’ PII after breach at third-party database operator Unknown parties know where you stayed last summer, down under, across 120 Quest properties
OpenAI's overhead will rise 20 percent for some workloads as it hardens security Expanded multistage chain of thought monitoring makes frontier model work more expensive
Expired credit cards revived by researchers to make unauthorized payments Gaps in expiry checks could let dead plastic make purchases again
CISA gives feds 3 days to fix actively exploited Ray RCE bug Phishing, malvertising attacks could target devs to gain access to private corporate networks
Apple plugs image-processing hole ripe for spyware abuse Patch batch spans current kit, older iGadgets, Macs, and Vision Pro
Copilot tricked into telling reseachers how to hack itself How to social engineer an AI's reasoning engine
Crook hawks millions of records allegedly plundered from corporate Azure tenants McDonald's, Vodafone, TCS, Kyndryl, and others named as researchers point to compromised credentials
Code fixers have fired up the AI warp drive. Strange new worlds await With more patches per month than at a pirate convention, the bug must be an endangered species. Well, about that
Black Hat and DEF CON are AI conferences now, too On this week's episode of The Reg's Kettle podcast, we revisit 'hacker summer camp,' where the hottest topic was ... sigh... agentic AI
Microsoft blames AI for delayed Exchange update, can’t say when it will arrive Dealing with machine-made bug backlog makes it hard to find a moment to deliver promised subscription service
Chinese AI company Zhipu claims its new model is a better bug-finder than Anthropic, OpenAI PLUS: HCL, TCS, admit data breaches; South Korea to fine Apple, Google; India bans some rideshare tips; and more!
Stopping a cyberattack while walking your dog - defensive AI security CEO says it's not ruff to do Corma CEO tells The Reg it's building 'One ring to rule them all, for the defenders to have this power'
ChainDrop worm crawls into npm supply chain, evades standard defenses Shai-Hulud variant poisons 444 packages, spreads via tarballs and dev-tool hooks
1.6M RingCentral accounts' data dumped after ShinyHunters extortion attack Another one bites the dust
French tax authority admits data heist after crook touts 2M records Government disputes claims of continued access as investigators measure damage
Autonomous AI attacks pose 'clear and present danger' to critical infrastructure Weaponized agents could turn digital intrusions into kinetic disasters, experts warn
Crypto wallet maker Trezor confirms 13,000 customers' details exposed in logistics breach Even if your hardware is secure, quantum-ready, encrypted, and future-proof, no one is immune to a supplier letting the side down
Scottish prosecutors cast eye over leaky supplier after staff data exposed Unnamed third party spotted suspicious activity, with names, roles, and email addresses potentially affected
New Zealand says China tried using space investments to spy on local affairs Intelligence Service says finding domestic threats is harder due to proliferation of toxic content online