security Fake Google Security Team ad says 'no script reading' in voice phishing - then prints the script More mockery and memes from the Dark Web Roast
cyber-crime ShinyHunters tells The Reg: We hacked the FBI to 'protect our business' Data theft and extortion biz, that is
security Crooks use fake desktop apps to fool HR staff into giving them remote access Nothing in the attack chain screams malicious software, except none of the impersonated HR and payroll providers actually offers a desktop app
cyber-crime Bitget blames North Korea for $387.5M crypto wallet raid Familiar fingerprints point to Kim’s regime … to the surprise of nobody
storage Which copy of that file is the real one? Dinner, off the record, in Midtown Joe Fay chairs a Register dinner in New York on the file infrastructure nobody has got around to replacing, with nothing on the record.
security Crook used three open source agents to break into a Fortune 500 hospitality company, a major US airline and 25+ other orgs Operator’s AI bill averaged just $25 per completed scan
security Salesforce Agentforce vulns allowed 0-click CRM data theft, anonymous phishing 'SalesBleed' security flaws 'lead to very unexpected consequences'
security Decades-old file security flaws found in Android, Linux, macOS, and Windows Security researchers report that Microsoft considers the side-channel leak of file events to be by design
os platforms CVE flood pushes Ubuntu onto weekly kernel release cycle AI-assisted bug hunting is helping pile up vulnerabilities faster than defenders can patch them, so Canonical is picking up the pace
security Someone went shopping in ASUS's eShop – for customer data Contact details and order records accessed, but PC maker is keeping schtum on how many customers are affected
security Google to critical infra orgs: Our AI scanners won't be evil, promise Gemini 3.8 Flash Cyber and Wiz's Red Agent team up to protect hospitals, public transit, and tech
security Government contractor exposed path to immigration records IT took a shortcut when the boss was away, and it led to danger!
security OpenAI agents ‘infiltrated Australian government website’ Canberra is fuming after AI lab sent the news to a generic unattended email address
security Someone's attacking a critical 0-day RCE in F5 BIG-IP APM Good news: there's a patch. Bad news: both CISA and F5 warn that it's under active exploitation
security Academic publisher Elsevier hit by LAPSUS$ redirect attack Customers got crime crew's calling card instead of access to journals
security Closing the observability gap for the AI-ready enterprise SPONSORED FEATURE: Why AI-driven operations need a data-rich view of the network
security British regulator takes a hard look at Pornhub's Apple-powered age checks Regulator wants to know whether parent Aylo did its homework before reopening the door to UK iPhone users
security Why security belongs in the network SPONSORED EXPLAINER: Merging security into the network makes enterprise protection more agile
security Windows CLOSEDQUORUM malware uses AI models to autonomously select post-compromise actions 'first' publicly documented Windows implant to use LLMs for C2
security NightmareEclipse's latest zero-day leaves Microsoft Defender stuck in the past BigDiskBuster leaves Microsoft's antivirus running but unable to install updates
security Z.ai says sorry for slurping up your code, open sources ZCode China’s AI darling goes on the defense after engineer highlighted Grok-esque security flaws
security UK cops arrest 2 EvilTokens suspects, Microsoft seizes 50 phishing kit websites Used by crims to compromise 12K+ email inboxes across 10K+ global orgs
security Who signed off on that AI agent? Nobody? Thought so. SPONSORED FEATURE: AI agents may be unpredictable. Who they are, what they can do, and who owns them shouldn’t be.
security Anthropic-linked CVEs pile up, attackers mostly shrug Of 225 flaws found by Glasswing and tracked by VulnCheck researcher, just one has confirmed exploitation in the wild
ai and ml Meta Muse AI app flaw lets local malware redirect dictation traffic Ad biz promises users control while bug could expose voice prompts
security Treasury chief says AI bosses, not their bots, will carry the can for criminal acts 'Humans are responsible, not the AI,' argues Scott Bessent as he calls out OpenAI agents' hack of Hugging Face
cyber-crime Clop gets a taste of its own medicine after ShinyHunters hijack leak site Rival crew demands eight figures and threatens to expose companies that paid to keep quiet
security Rustaceans warned of job interviews with a malicious payload Attackers are courting crate owners with plausible company profiles and booby-trapped recruitment calls
security Agentic security is the billion-dollar challenge for some clever startup to solve High time to stop kicking the security can down the road, investor tells The Reg
security Researchers used Claude to hack OpenAI employees' ChatGPT accounts Agentic exploits for the win (again)
security North Korea's fake job interviews infected 30,000 devices WaterPlum recruiters used bogus coding tests to backdoor jobseekers and raid more than 7,000 crypto wallets
cyber-crime FBI: Fake cop and government impersonation scams cost victims $1.6B AI, fake uniforms, and mock offices help crooks sell the con
security USA’s Venezuela takeover comes with bonus exposure to Chinese AI surveillance tech Think tank points out that companies banned by Washington will help run the regime that Uncle Sam now controls
security AI coding agents' 0-click RCE flaw could hand attackers keys to the kingdom Plugin4Shell attack affects all the major coding agents, researchers say
security Researchers find way to listen in on headphones from afar Eve's dropping in on Alice and Bob
security China's Salt Typhoon backdoors Latin American orgs with new snooping malware Beware the SparroWocky, my son! The backdoor that bites…
security London property manager breach may have exposed bank details and lockbox codes City Relay says intruders accessed its Metabase Cloud instance twice and extracted customer data
security Cisco drops another exploited zero-day, this time a perfect 10 ISE authentication bypass under active attack just days after another Cisco zero-day sent admins scrambling to patch
security Test environment let anyone access live customer data Even a temporary staging server needs to be locked down.
security Ofcom discovers issuing Online Safety Act fines is easier than collecting them Platforms comply just enough to avoid being blocked, leaving the regulator chasing debt
security AI agents can modify themselves without humans telling them to do so This is a test - it is only a test
security CISA decides weekly vulnerability bulletin isn't necessary anymore Agency's shift from static CVSS scores to risk-based prioritization sends the old format packing September 28
security Google Pixel phones pwned in zero-click attacks CISA gives federal agencies just 3 days to patch
cyber-crime Spain gets its first taste of AI-aided cyber attack Data protection chiefs call for 'immediate review' of data protection models
security Ministry of Justice apologizes after court staff accessed Southport victims' files Sensitive personal data was involved, but there is no evidence it was shared with third parties
Mythos has made 2026 patching hell. It might make 2027 a breeze Gartner sees huge amounts of technical debt paid down, and better scanning that could make software safer sooner
The vulnpocalypse rains iBugs down on Apple with record-setting number of patches September Patch Tuesday part 2?
security Low-quality casino sites conceal highly dangerous threat actors Security firm Infoblox shines light on malicious infrastructure lurking beneath illegal gambling sites
security Iranian spies hit Windows machines with Chosen Brick data-stealing malware 'Enemies of the regime' on notice
security Cisco email security boxes can be rooted by... an email Attackers already exploiting the critical flaw, and Cisco warns they may be able to cover their tracks once they're in
security Who's governing your AI? A trust framework for enterprise agents and models SPONSORED FEATURE: DigiCert wants to hand every agent a passport, an expiry date and a named human owner
security Swiss court sentences 52-year-old Ukrainian ransomware dev to nearly 13 years in the cooler The man allegedly wrote the code that powered the Lockergoga, MegaCortex, and Nefilim operations
ai and ml The latest AI doomsayer is China’s intelligence boss Beijing’s response is to ‘firmly grasp technological sovereignty’ and broad regulations
HBO Max Reddit account compromised to serve ClickFix attacks Part of a 'massive 48-hour malvertising blitz' targeting macOS and Windows machines with malware
security New hardware device can RAM into encrypted memory, expose your data Attackers would need physical access to the server to pull off the DDR5 trick
security OpenAI's malicious bot swarm attacked RubyGems Ruby are you ok? Ruby are you ok? Are you ok Ruby?
security Perfect-10 GitLab bug under attack days after patch lands CISA confirms active exploitation as watchTowr spots miscreants probing internet-facing servers
security UK.gov begins killing off passwords for 23 million users Passkeys promise fewer phishing headaches – and £600 a day off Whitehall's SMS bill
security Security through obscurity is dead, and AI delivered the fatal blow RIP, you won't be mourned
security More JFrog Artifactory bugs under attack, and all 3 have patches If you're waiting for a sign to upgrade to a fixed version: this is it
cyber-crime Ukrainian lawyer's second career as a Conti coder earns him 4 years behind bars Swapping legal work for malware development ended in extradition and a guilty plea
security EU's Cyber Resilience Act starts the 24-hour vulnerability clock Manufacturers must now disclose actively exploited flaws and severe security incidents through ENISA's new reporting platform
ai and ml Latest Anthropic horror story chills with tales of kamikaze drone swarms and bioweapons research Everyone from ShinyHunters to Russian freelancers is in on the illicit model fun
security Watch out: Apple timepiece can grab snippets of conversation without both speakers' consent War is peace. Freedom is slavery. Privacy is surveillance
security Hundreds of AI agents helped PaperCut attacker hit 395+ orgs, and some went off script Human operator: don't touch CIS orgs. AI agents: look a squirrel!
security ShinyHunters expose 6.4M in attack on medical supplier McKesson Have I Been Pwned logs leaked records spanning patients, staff, and providers
security Dental contractor set up secret account with access to 4,000 patient records then left the company Toothless security
ai and ml Anthropic reveals fourth likely crime committed by its AI Claude's Felony Bench rap sheet is now as long as OpenAI's
research Novel Blue Moon kit targeting Chrome and Windows reflects new reality of AI-driven exploits Mind the patch gap, please and thank you
security Serial Microsoft 0-day hunter drops yet another Defender exploit A bypass of a bypass of a bypass
security WeChat worm could pwn a friend before they even answered the call Calif says AI helped turn a VoIP memory bug into cross-platform RCE before Tencent shut it down
security Microsoft breaks Patch Tuesday record with 974-CVE deluge Adobe also brought goodies to the patch party and they deserve immediate attention
security OpenAI's Artifactory opened covert data-stealing channel alongside Hugging Face attack Researchers disclosed the cross-account trick the same day rogue agents exploited another zero-day for admin access
security Boston Scientific left nursing its bottom line after cyberattack Medical device giant warns August intrusion will hit Q3 and full-year sales and earnings as recovery drags on
security How to secure hybrid meeting rooms without sacrificing user experience SPONSORED FEATURE: With regulators tightening rules and attack surfaces widening, meeting-room kit must bake in security without pushing users toward workarounds
security LG accused of 'egregious invasion of privacy' over TV data collection Claims follow scrutiny over monitors installing adware without user consent
security BigBear phishing crew nets thousands of Microsoft 365 credentials Researchers got inside the crooks' admin panel and found 5,137 stolen records tied to 461 organizations
research Extortion crews have their eyes on high-value AI data, Google warns Companies 'don't want their IP exposed, so they're willing to pay'
public sector Britain reboots its space strategy with £7.8B already on the launchpad Cross-government plan combines civil ambitions with an increasingly military view of orbit
security Nightwing CEO has a Labor Day message for staff – and apparently The Register Nothing says ‘For internal use only’ quite like emailing it to the press
security Hackers drain $320M in Bitcoin from Liquid Network, claim they're the good guys Self-described white hats promise to return 'most' of the 4,000 BTC once the vulnerability is fixed
security Welsh environment regulator's FoI blunder exposes diversity data of 2,000 staff NRW says it has found no evidence data was misused after spreadsheet published in error five years ago
security UK food supply chain at risk from hostile attacks Defending against cyber foes is among factors hitting food price inflation, report finds
security Peers ask why UK cyber bill leaves execs off the personal liability hook Ministers say £17M corporate fines and forthcoming board-level governance rules provide sufficient accountability
security ASCII smuggling isn't just an AI security risk Phishers find a new use for invisible Unicode tag characters
ai and ml Rogue OpenAI agents used dead German web site to communicate in May, months before Hugging Face incident Two cases of agents escaping to solve unsolvable problems paints an uncomfortable question: Is the entire internet in OpenAI's experimental agentic firing line?
security Cisco searched for IOS XR bugs and found so many it rolled them into an update release Three critical vulns demand your attention, one a make-me-root mess in Nexus 9000 Series Switches that you can mitigate, not fix
security OpenAI commits $1B in AI credits to frontline cyber defenders Daybreak program brings subsidized models, training, and support to under-resourced teams
security Prolific Microsoft 0-day hunter drops CrowdStrike Falcon exploit PoC A shared security 'Nightmare'
security Drowning in CVEs and thirsty for answers? Try CTEM SPONSORED FEATURE: Boards want to know if they're less exposed than last quarter. Patching metrics aren't the solution
cyber-crime Cybercrooks trawl Fishbrain to net password hashes Armed with password hashes and salts, attackers could already be kraken those creds
security Terminated employee cost company hundreds of thousands of dollars because nobody revoked access
security AI agents carried out every step of this ransomware attack – then left the victim an 80-page security audit
cyber-crime Cops, CrowdStrike disrupt Sality botnet by poisoning the network and diverting into sinkholes
security FBI seizes hacking tools it says China used to attack NASA, DOE, US Senate and other critical networks
security AliExpress accused of fingerprinting shoppers with silent audio trick that also muted a dev's headphones
security 'Not a theoretical risk,' feds warn as attackers use AI-made code to hack critical infrastructure controllers
security Stopping a cyberattack while walking your dog - defensive AI security CEO says it's not ruff to do
security Signal adds an extra layer of security to make sure you're actually chatting with the right person
security Water system controllers don't belong on the internet, says ex-NSA chief after suspected Iran attacks
networks N-able God mode flaw: Vendor confirms attackers reached customer networks as second hotfix lands
security Scot NHS trust probes access to medical records of 9-year-old girl after man arrested on suspicion of murder