News

Another npm supply chain worm is tearing through dev environments

The Register - Wed, 22/04/2026 - 23:34
Plus, the payload references 'TeamPCP/LiteLLM method'

Yet another npm supply-chain attack is worming its way through compromised packages, stealing secrets and sensitive data as it moves through developers' environments, and it shares significant overlap with the open source infections attributed to TeamPCP last month.…

Categories: News

Anthropic's super-scary bug hunting model Mythos is shaping up to be a nothingburger

The Register - Wed, 22/04/2026 - 22:39
Hackpocalypse deferred

Anthropic's Mythos model is purportedly so good at finding vulnerabilities that the Claude-maker is afraid to make it available to the general public for fear that criminals will take advantage. But early analysis shows that Mythos may not be as dangerous as some would have you believe.…

Categories: News

Google unleashes even more AI security agents to fight the baddies

The Register - Wed, 22/04/2026 - 13:01
Along with a bunch of new services to make sure those same agents don't cause chaos

Google Cloud chief operating officer Francis deSouza has summed up his company's security strategy du jour as follows: "You need to use AI to fight AI."…

Categories: News

France's 'Secure' ID agency probes breach as crooks claim 19M records

The Register - Wed, 22/04/2026 - 12:30
Gov admits 'incident' as forum sellers boast of fresh haul covering up to a third of the population

France's National Agency for "Secure" Documents is explaining a potential data spill just as crooks online claim they've nicked a third of the country's ID information.…

Categories: News

Scotland Yard can keep using live facial recognition on people in London, say judges

The Register - Wed, 22/04/2026 - 12:14
Judges say cops face-slurping not a problem under current human rights laws

London's Metropolitan Police Service (MPS) has survived a legal challenge that attempted to curb its rollout of live facial recognition (LFR) technology across the capital.…

Categories: News

Oil crisis? What oil crisis? IT spending de-coupled from wider war shock

The Register - Wed, 22/04/2026 - 09:30
Gartner sees accelerating growth in IT spending, powered by cloud and AI infrastructure investment

A day after the International Energy Agency (IEA) said the US/Israel/Iran war was creating the worst energy crisis ever faced by the ‌world, Gartner increased its growth forecasts for global IT spending by nearly three percentage points.…

Categories: News

Mythos found 271 Firefox flaws – but none a human couldn’t spot

The Register - Wed, 22/04/2026 - 05:32
Mozilla CTO says AI means developers finally have a chance to get on top of security

The Mozilla Foundation has revealed it tested Anthropic’s bug-finding “Mythos” AI model and feels the results it experienced represent a watershed moment for software defenders.…

Categories: News

Nation-states want to cause harm, not just steal cash - stop handing your cyber defenses to the cheapest contractor

The Register - Tue, 21/04/2026 - 22:30
NCSC boss says China's whole-of-state cyber machine has become Britain's peer competitor in cyberspace

State-sponsored cyberattacks from Chinese intelligence and military agencies display "an eye-watering level of sophistication," UK National Cyber Security Centre CEO Richard Horne is expected to say in a less-than-cheery opening speech to kick off its annual conference.…

Categories: News

Murder, she wrote: Ex-FBI chief wants some ransomware crims charged with homicide

The Register - Tue, 21/04/2026 - 21:26
Lawmakers decry CISA cuts: 'We are shooting ourselves in the foot'

If a cyberattack leads to a death, that's murder. A former FBI cyber division chief urged the US Justice Department to consider felony homicide charges against ransomware actors when attacks on hospitals lead to patient deaths.…

Categories: News

More Cisco SD-WAN bugs battered in attacks

The Register - Tue, 21/04/2026 - 18:30
CISA gives federal agencies 4 days to patch

America's lead cyber-defense agency has warned that three Cisco Catalyst SD-WAN Manager bugs are under attack, and given federal agencies just four days to patch the security holes.…

Categories: News

macOS ClickFix attacks deliver AppleScript stealers to snarf credentials, wallets

The Register - Tue, 21/04/2026 - 16:50
Data from browsers, cryptocurrency wallets, 200+ extensions hoovered up

A ClickFix campaign targeting macOS users delivers an AppleScript-based infostealer that collects credentials and live session cookies from 14 browsers, 16 cryptocurrency wallets, and more than 200 extensions.…

Categories: News

Yet another ex-ransomware negotiator admits turning rogue after payoff from crimelords

The Register - Tue, 21/04/2026 - 15:15
Plus: Court papers reveal nonprofit paid a ransom worth nearly $26.8 million

The third of three former ransomware negotiators accused of assisting the ALPHV/BlackCat ransomware gang in extorting US businesses has pleaded guilty, months after his two co-workers did the same.…

Categories: News

AI-assisted intruders pwned Vercel via OAuth abuse and a pilfered employee account

The Register - Tue, 21/04/2026 - 13:17
CEO suspects silicon sidekick behind 'surprising velocity' breach - cyber crims shop stolen data for $2M

Vercel's CEO reckons the crooks behind its recent breach likely had a helping hand from AI, saying the attackers moved with "surprising velocity" and a deep understanding of the company's infrastructure.…

Categories: News

Crook claims to leak 'video surveillance footage' of companies

The Register - Tue, 21/04/2026 - 12:30
Mexican IT services firm admits it was hacked, but says client operations weren't affected

A Mexican IT infrastructure and digital transformation biz is on clean-up duty after a criminal posted screenshots of what they claimed was company video surveillance footage to a cybercrime forum.…

Categories: News

Met police trials snoop tech platform in push to cuff more London shoplifters

The Register - Tue, 21/04/2026 - 11:52
No facial recognition privacy intrusions either! Well, maybe a little

London's Metropolitan Police is trialing new retail technology to help curtail the city's pervasive shoplifting problem… and it doesn't rely on live facial recognition (LFR).…

Categories: News

Adaptavist Group breach spawns imposter emails as ransomware crew claims mega-haul

The Register - Tue, 21/04/2026 - 09:30
Fake emails already doing the rounds as ransomware crew boasts about what it allegedly stole

UK enterprise software consultancy The Adaptavist Group is investigating a security breach after an intruder logged in with stolen credentials, while a ransomware crew claims it grabbed far more than the company is currently admitting.…

Categories: News

Panasonic creates device-locked QR codes to speed facial biometric capture

The Register - Tue, 21/04/2026 - 08:37
Admins are tired of taking photos, so this enables secure on-site unattended enrolment

Japanese industrial giant Panasonic has created a new form of QR code it says will only work on designated devices and environments.…

Categories: News

Iran claims US used backdoors to knock out networking equipment during war

The Register - Tue, 21/04/2026 - 07:21
And China is loving it

Iranian media is claiming that the US used backdoors and/or botnets to disable networking equipment during the current war, and Chinese state media is dining out on the allegations.…

Categories: News

Vibe coding upstart Lovable denies data leak, cites 'intentional behavior,' then throws HackerOne under the bus

The Register - Tue, 21/04/2026 - 00:26
A lesson in how not to respond to vulnerability reports

Vibe-coding platform Lovable is pooh-poohing a researcher’s finding that anyone could open a free account on the service and read other users' sensitive info, including credentials, chat history, and source code. However, the company’s story keeps changing: First it attributed the publicly exposed info to "intentional behavior" and "unclear documentation," then threw bug-bounty service HackerOne under the bus.…

Categories: News

Claude Desktop changes app access settings for browsers you don't even have installed yet

The Register - Mon, 20/04/2026 - 20:56
Installation and pre-approval without consent looks dubious under EU law

One app should not modify another app without asking for and receiving your explicit consent. Yet Anthropic's Claude Desktop for macOS installs files that affect other vendors' applications without disclosure, even before those applications have been installed, and authorizes browser extensions without consent.…

Categories: News

Pages

Subscribe to Sec Tec Limited aggregator - News