News

Supply chain attacks now fuel a 'self-reinforcing' cybercrime economy

The Register - 2 hours 3 min ago
Researchers say breaches link identity abuse, SaaS compromise, and ransomware into a cascading cycle

Cybercriminals are turning supply chain attacks into an industrial-scale operation, linking breaches, credential theft, and ransomware into a "self-reinforcing" ecosystem, researchers say.…

Categories: News

Feeling brave? Ministry of Defence seeks £300K digital boss to manage £4.6B spend

The Register - 3 hours 47 min ago
Whoever gets it will steer UK department's IT, AI strategy, and megabucks vendor deals

The UK Ministry of Defence (MoD) is offering between £270,000 to £300,000 for a senior digital leader who will oversee more than £4.6 billion in spending and more than 3,000 specialist staff.…

Categories: News

Google: China's APT31 used Gemini to plan cyberattacks against US orgs

The Register - 7 hours 2 min ago
Meanwhile, IP-stealing 'distillation attacks' on the rise

A Chinese government hacking group that has been sanctioned for targeting America's critical infrastructure used Google's AI chatbot, Gemini, to auto-analyze vulnerabilities and plan cyberattacks against US organizations, the company says.…

Categories: News

Microsoft warns that poisoned AI buttons and links may betray your trust

The Register - 12 hours 55 min ago
Businesses are embedding prompts that produce content they want you to read, not the stuff AI makes if left to its own devices

Amid its ongoing promotion of AI’s wonders, Microsoft has warned customers it has found many instances of a technique that manipulates the technology to produce biased advice.…

Categories: News

Devilish devs spawn 287 Chrome extensions to flog your browser history to data brokers

The Register - Wed, 11/02/2026 - 21:23
Add-ons with 37M installs leak visited URLs to 30+ recipients, researcher says

They know where you've been and they're going to share it. A security researcher has identified 287 Chrome extensions that allegedly exfiltrate browsing history data for an estimated 37.4 million installations.…

Categories: News

Posting AI-generated caricatures on social media is risky, infosec killjoys warn

The Register - Wed, 11/02/2026 - 18:56
The more you share online, the more you open yourself to social engineering

If you've seen the viral AI work pic trend where people are asking ChatGPT to "create a caricature of me and my job based on everything you know about me" and sharing it to social, you might think it's harmless. You'd be wrong.…

Categories: News

Were telcos tipped off to *that* ancient Telnet bug? Cyber pros say the signs stack up

The Register - Wed, 11/02/2026 - 15:41
Curious port filtering and traffic patterns suggest advisories weren’t the earliest warning signals sent

Telcos likely received advance warning about January's critical Telnet vulnerability before its public disclosure, according to threat intelligence biz GreyNoise.…

Categories: News

Payroll pirates are conning help desks to steal workers' identities and redirect paychecks

The Register - Wed, 11/02/2026 - 13:00
Attackers using social engineering to exploit business processes, rather than tunnelling in via tech

Exclusive  When fraudsters go after people's paychecks, "every employee on earth becomes a target," according to Binary Defense security sleuth John Dwyer.…

Categories: News

Notepad's new Markdown powers served with a side of remote code execution

The Register - Wed, 11/02/2026 - 11:31
Smug faces across all those who opposed the WordPad-ification of Microsoft's humble text editor

Just months after Microsoft added Markdown support to Notepad, researchers have found the feature can be abused to achieve remote code execution (RCE).…

Categories: News

Legacy systems blamed as ministers promise no repeat of Afghan breach

The Register - Wed, 11/02/2026 - 09:30
UK government grilled over progress made to prevent a second life-threatening leak

Legacy IT issues are hampering key technical measures designed to prevent highly sensitive data leaks, UK government officials say.…

Categories: News

Microsoft's Valentine's gift to admins: 6 exploited zero-day fixes

The Register - Tue, 10/02/2026 - 22:10
Roses are red, violets are blue ... now get patching

What better way to say I love you than with an update? Attackers exploited a whopping six Microsoft bugs as zero-days prior to Redmond releasing software fixes on February's Patch Tuesday.…

Categories: News

AI agents spill secrets just by previewing malicious links

The Register - Tue, 10/02/2026 - 17:55
Zero-click prompt injection can leak data when AI agents meet messaging apps, researchers warn

AI agents can shop for you, program for you, and, if you're feeling bold, chat for you in a messaging app. But beware: attackers can use malicious prompts in chat to trick an AI agent into generating a data-leaking URL, which link previews may fetch automatically.…

Categories: News

Singapore spent 11 months booting China-linked snoops out of telco networks

The Register - Tue, 10/02/2026 - 13:43
Operation Cyber Guardian involved 100-plus staff across government and industry

Singapore spent almost a year flushing a suspected China-linked espionage crew out of its telecom networks in what officials describe as the country's largest cyber defense operation to date.…

Categories: News

Nearly 17,000 Volvo staff dinged in supplier breach

The Register - Tue, 10/02/2026 - 11:09
HR outsourcer Conduent confirms intruders accessed benefits-related records tied to US personnel

Nearly 17,000 Volvo employees had their personal data exposed after cybercriminals breached Conduent, an outsourcing giant that handles workforce benefits and back-office services.…

Categories: News

British Army splashes $86M on AI gear to speed up the battlefield kill chain

The Register - Tue, 10/02/2026 - 10:00
Troops fitted with new comms kit as part of Project ASGARD

British soldiers are to get an array of AI-ready kit that should mean they don't have to wait to see the "whites of their eyes" before pulling the trigger.…

Categories: News

Someone's attacking SolarWinds WHD to steal high‑privilege credentials - but we don't know who or how

The Register - Mon, 09/02/2026 - 21:54
So many CVEs, so little time

Digital intruders exploited buggy SolarWinds Web Help Desk (WHD) instances in December to break into victims' IT environments, move laterally, and steal high-privilege credentials, according to Microsoft researchers.…

Categories: News

More than 135,000 OpenClaw instances exposed to internet in latest vibe-coded disaster

The Register - Mon, 09/02/2026 - 17:23
By default, the bot listens on all network interfaces, and many users never change it

It's a day with a name ending in Y, so you know what that means: Another OpenClaw cybersecurity disaster.…

Categories: News

Dutch data watchdog snitches on itself after getting caught in Ivanti zero-day attacks

The Register - Mon, 09/02/2026 - 14:50
Staff data belonging to the regulator and judiciary's governing body accessed

The Dutch Data Protection Authority (AP) says it was one of the many organizations popped when attackers raced to exploit recent Ivanti vulnerabilities as zero-days.…

Categories: News

Taiwan tells Uncle Sam its chip ecosystem ain't going anywhere

The Register - Mon, 09/02/2026 - 14:02
Moving 40% of semiconductor production to America is 'impossible' says vice premier

Taiwan's vice-premier has ruled out relocating 40 percent of the country's semiconductor production to the US, calling the Trump administration's goal "impossible."…

Categories: News

How the GNU C Compiler became the Clippy of cryptography

The Register - Mon, 09/02/2026 - 12:07
Security devs forced to hide Boolean logic from overeager optimizer

FOSDEM 2026  The creators of security software have encountered an unlikely foe in their attempts to protect us: modern compilers.…

Categories: News

Pages

Subscribe to Sec Tec Limited aggregator - News