News

Browser 'privacy' extensions have eye on your AI, log all your chats

The Register - 25 min 56 sec ago
More than 8 million people have installed extensions that eavesdrop on chatbot interactions

Ad blockers and VPNs are supposed to protect your privacy, but four popular browser extensions have been doing just the opposite. According to research from Koi Security, these pernicious plug-ins have been harvesting the text of chatbot conversations from more than 8 million people and sending them back to the developers.…

Categories: News

SantaStealer stuffs credentials, crypto wallets into a brand new bag

The Register - 2 hours 31 min ago
All I want for Christmas … is all of your data

A new, modular infostealer called SantaStealer, advertised on Telegram with a basic tier priced at $175 per month, promises to make criminals' Christmas dreams come true. It boasts that it can run "fully undetected" even on systems with the "strictest AntiVirus" and those belonging to governments, financial institutions, and other prime targets.…

Categories: News

From pr0n to playlists and paperclips, trio of breaches spills data of millions

The Register - 8 hours 56 min ago
Adult site, streaming platform, and Japanese retailer expose user info, but not credentials

Three very different companies have now confirmed data breaches affecting millions of users – each insisting the damage stopped well short of passwords and payment details.…

Categories: News

MI6 chief: we'll be as fluent in Python as we are in Russian

The Register - 9 hours 44 min ago
New spy boss says officers must master code alongside tradecraft as agency navigates 'space between peace and war'

MI6's new chief Blaise Metreweli outlined her vision for technology-augmented intelligence gathering in her first public speech on 15 December, warning that the UK operates "in a space between peace and war."…

Categories: News

PwC on using AI to turn cybersecurity risk into competitive advantage

The Register - 15 hours 39 min ago
PwC supports clients across the full cyber lifecycle

Sponsored Post  Managing cybersecurity risk has never been simple, but in today's threat landscape it can also become a source of strength. PwC believes that AI is now central to that transformation, helping organizations not just react faster to attacks, but evolve their defences with greater confidence.…

Categories: News

No, SoundCloud hasn’t started tuning out VPNs. It’s mopping up after a cyberattack

The Register - 16 hours 9 min ago
Bum note for 20 percent of users whose data leaked

Music hosting and streaming service SoundCloud has admitted it suffered a cyberattack.…

Categories: News

Amazon security boss blames Russia's GRU for years-long energy-sector hacks

The Register - Mon, 15/12/2025 - 23:34
'Sustained focus on Western critical infrastructure'

Russia's Main Intelligence Directorate (GRU) is behind a years-long campaign targeting energy, telecommunications, and tech providers, stealing credentials and compromising misconfigured devices hosted on AWS to give the Kremlin's snoops persistent access to sensitive networks, according to Amazon's security boss.…

Categories: News

China, Iran are having a field day with React2Shell, Google warns

The Register - Mon, 15/12/2025 - 17:53
Who hasn't exploited this max-severity flaw?

At least five more Chinese spy crews, Iran-linked goons, and financially motivated criminals are now attacking React2Shell, a maximum-severity flaw in the widely used React JavaScript library, according to Google.…

Categories: News

Delay to European Central Bank messaging project cost the Bank of England £23M

The Register - Mon, 15/12/2025 - 12:50
Watchdog links schedule change to replanning of UK payments system overhaul

The European Central Bank's (ECB) decision to delay its move to a new messaging standard in 2022 ended up costing the Bank of England £23 million as it was forced to adjust migration to a new settlement system to avoid compounding risks.…

Categories: News

JLR: Payroll data stolen in cybercrime that shook UK economy

The Register - Mon, 15/12/2025 - 12:08
Automaker admits raid that crippled its factories in August led to the theft of sensitive info

Jaguar Land Rover (JLR) has reportedly told staff the cyber raid that crippled its operations in August didn't just bring production to a screeching halt – it also walked off with the personal payroll data of thousands of employees.…

Categories: News

Apple, Google forced to issue emergency 0-day patches

The Register - Mon, 15/12/2025 - 11:01
Both admit attackers were already exploiting the bugs, with scant detail and hints of spyware-grade abuse

Apple and Google have both issued emergency patches after zero-day bugs were caught being actively exploited in what the companies describe as "sophisticated" real-world attacks.…

Categories: News

Denmark takes a Viking swing at VPN-enabled piracy

The Register - Mon, 15/12/2025 - 10:40
Minister insists 'modest' bill is not an assault on privacy-preserving tech

The Danish government wants the public to weigh in on its proposed laws restricting use of VPNs to access certain corners of the internet.…

Categories: News

Legal protection for ethical hacking under Computer Misuse Act is only the first step

The Register - Mon, 15/12/2025 - 09:30
I'm dreaming of a white hat mass

Opinion  It was 40 years ago that four young British hackers set about changing the law, although they didn't know it at the time. It was a cross-platform attack including a ZX Spectrum, a BBC Micro, and a Tatung Einstein slamming British Telecom's Prestel service over dial-up modems at 75 bits per second.…

Categories: News

Starlink claims Chinese launch came within 200 meters of broadband satellite

The Register - Mon, 15/12/2025 - 02:02
PLUS: Drugs found in ink cartridges; Chinse censorship fighters criticize Vultr; Coupang CEO resigns; And more!

Asia In Brief  A SpaceX executive has claimed that a Chinese satellite launch came within 200 meters of hitting a Starlink satellite.…

Categories: News

Honeypots can help defenders, or damn them if implemented badly

The Register - Sun, 14/12/2025 - 23:26
PLUS: Crims could burn your AI budgets thanks to weak defaults; CISA's top 25 vulns for 2025; And more

Infosec In Brief  The UK's National Cyber Security Centre (NCSC) has found that cyber-deception tactics such as honeypots and decoy accounts designed to fool attackers can be useful if implemented very carefully.…

Categories: News

Microsoft RasMan DoS 0-day gets unofficial patch - and a working exploit

The Register - Fri, 12/12/2025 - 22:29
Exploit hasn't been picked up by any malware detection engines, CEO tells The Reg

A Microsoft zero-day vulnerability that allows an unprivileged user to crash the Windows Remote Access Connection Manager (RasMan) service now has a free, unofficial patch - with no word as to when Redmond plans to release an official one - along with a working exploit circulating online.…

Categories: News

New React vulns leak secrets, invite DoS attacks

The Register - Fri, 12/12/2025 - 18:23
And the earlier React2Shell patch is vulnerable

If you're running React Server Components, you just can't catch a break. In addition to already-reported flaws, newly discovered bugs allow attackers to hang vulnerable servers and potentially leak Server Function source code, so anyone using RSC or frameworks that support it should patch quickly.…

Categories: News

Microsoft promises more bug payouts, with or without a bounty program

The Register - Fri, 12/12/2025 - 13:35
Critical vulnerabilities found in third-party applications eligible for award under 'in scope by default' move

Microsoft is overhauling its bug bounty program to reward exploit hunters for finding vulnerabilities across all its products and services, even those without established bounty schemes.…

Categories: News

Uncle Sam sues ex-Accenture manager over Army cloud security claims

The Register - Fri, 12/12/2025 - 13:25
Justice Department alleges federal auditors were misled over compliance with FedRAMP and DoD requirements

The US is suing a former senior manager at Accenture for allegedly misleading the government about the security of an Army cloud platform.…

Categories: News

UK watchdog urged to probe GDPR failures in Home Office eVisa rollout

The Register - Fri, 12/12/2025 - 12:36
Rights groups say digital-only record is leaking data and courting trouble

Civil society groups are urging the UK's data watchdog to investigate whether the Home Office's digital-only eVisa scheme is breaching GDPR, sounding the alarm about systemic data errors and design failures that are exposing sensitive personal information while leaving migrants unable to prove their lawful status.…

Categories: News

Pages

Subscribe to Sec Tec Limited aggregator - News