News

Fortinet finally cops to critical make-me-admin bug under active exploitation

The Register - Fri, 14/11/2025 - 20:39
More than a month after PoC made public

Fortinet finally published a security advisory on Friday for a critical FortiWeb path traversal vulnerability under active exploitation – but it appears digital intruders got a month's head start.…

Categories: News

Crims poison 150K+ npm packages with token-farming malware

The Register - Fri, 14/11/2025 - 18:22
Amazon spilled the TEA

Yet another supply chain attack has hit the npm registry in what Amazon describes as "one of the largest package flooding incidents in open source registry history" - but with a twist. Instead of injecting credential-stealing code or ransomware into the packages, this one is a token farming campaign.…

Categories: News

FBI flags scam targeting Chinese speakers with bogus surgery bills

The Register - Fri, 14/11/2025 - 16:16
Crooks spoof US insurers, threaten bogus extradition to pry loose personal data and cash

Chinese speakers in the US are being targeted as part of an aggressive health insurance scam campaign, the FBI warns.…

Categories: News

CISA flags imminent threat as Akira ransomware starts hitting Nutanix AHV

The Register - Fri, 14/11/2025 - 15:02
Advisory updated as leading cybercrime crew opens up its target pool

The US Cybersecurity and Infrastructure Security Agency (CISA) has issued new guidance to organizations on the Akira ransomware operation, which poses an imminent threat to critical sectors.…

Categories: News

Clop claims it hacked 'the NHS.' Which bit? Your guess is as good as theirs

The Register - Fri, 14/11/2025 - 09:30
Cybercrime crew has ravaged multiple private organizations using Oracle EBS zero-day for months

The UK's National Health Service (NHS) is investigating claims of a cyberattack by extortion crew Clop.…

Categories: News

Kubernetes overlords decide Ingress NGINX isn’t worth saving

The Register - Fri, 14/11/2025 - 01:12
Maintenance to end next year after ‘helpful options’ became ‘serious security flaws’

Kubernetes maintainers have decided it’s not worth trying to save Ingress NGINX and will instead stop work on the project and retire it in March 2026.…

Categories: News

Chinese spies told Claude to break into about 30 critical orgs. Some attacks succeeded

The Register - Thu, 13/11/2025 - 23:12
Anthropic dubs this the first AI-orchestrated cyber snooping campaign

Chinese cyber spies used Anthropic's Claude Code AI tool to attempt digital break-ins at about 30 high-profile companies and government organizations – and the government-backed snoops "succeeded in a small number of cases," according to a Thursday report from the AI company.…

Categories: News

Ransomed CTO falls on sword, refuses to pay extortion demand

The Register - Thu, 13/11/2025 - 20:02
Checkout.com will instead donate the amount to fund cybercrime research

Ransomware is a huge business, because affected orgs keep forking over money to get their data back. However, instead of paying a ransom demand after getting hit by extortionists last week, payment services provider Checkout.com donated the demanded amount to fund cybercrime research.…

Categories: News

Ubuntu 25.10's Rusty sudo holes quickly welded shut

The Register - Thu, 13/11/2025 - 15:45
The goal of 'oxidizing' the Linux distro hits another bump

Two vulnerabilities in Ubuntu 25.10's new "sudo-rs" command have been found, disclosed, and fixed in short order.…

Categories: News

Extra, extra, read all about it: Washington Post clobbered in Clop caper

The Register - Thu, 13/11/2025 - 13:45
Nearly 10,000 staff and contractors warned after attackers raided newspaper's Oracle EBS setup

The Washington Post has confirmed that nearly 10,000 employees and contractors had sensitive personal data stolen in the Clop-linked Oracle E-Business Suite (EBS) attacks.…

Categories: News

Rhadamanthys malware admin rattled as cops seize a thousand-plus servers

The Register - Thu, 13/11/2025 - 12:01
Operation Endgame also takes down Elysium and VenomRAT infrastructure

International cops have pulled apart the Rhadamanthys infostealer operation, seizing 1,025 servers tied to the malware in coordinated raids between November 10-13.…

Categories: News

NHS supplier ends probe into ransomware attack that contributed to patient death

The Register - Thu, 13/11/2025 - 11:13
Synnovis's 18-month forensic review of Qilin intrusion completed, now affected patients to be notified

Synnovis has finally wrapped up its investigation into the 2024 ransomware attack that crippled pathology services across London, ending an 18-month effort to untangle what the NHS supplier describes as one of the most complex data reconstruction jobs it has ever faced.…

Categories: News

Google sues 25 China-based scammers behind Lighthouse 'phishing for dummies' kit

The Register - Wed, 12/11/2025 - 21:39
600+ phishing websites and 116 of these use a Google logo

Google has filed a lawsuit against 25 unnamed China-based scammers, which it claims have stolen more than 115 million credit card numbers in the US as part of the Lighthouse phishing operation.…

Categories: News

Attackers turned Citrix, Cisco 0-day exploits into custom-malware hellscape

The Register - Wed, 12/11/2025 - 17:16
Vendors (still) keep mum

An "advanced" attacker exploited CitrixBleed 2 and a max-severity Cisco Identity Services Engine (ISE) bug as zero-days to deploy custom malware, according to Amazon Chief Information Security Officer CJ Moses.…

Categories: News

Bitcoin bandit's £5B bubble bursts as cops wrap seven-year chase

The Register - Wed, 12/11/2025 - 11:21
Metropolitan Police lands lengthy sentence following 'complex' investigation

The Metropolitan Police's seven-year investigation into a record-setting fraudster has ended after she was sentenced to 11 years and eight months in prison on Tuesday.…

Categories: News

UK's Cyber Security and Resilience Bill makes Parliamentary debut

The Register - Wed, 12/11/2025 - 10:54
Various touch-ups added as MPs seek greater resilience to attacks on critical sectors

UK government introduced the Cyber Security and Resilience (CSR) Bill to Parliament today, marking a significant overhaul of local cybersecurity legislation to sharpen the security posture of the most critical sectors.…

Categories: News

Aviation watchdog says organized drone attacks will shut UK airports ‘sooner or later’

The Register - Wed, 12/11/2025 - 10:15
Skies are open for mischief as hard-to-trace drones and fast-moving cyber raids promise new wave of disruption

Britain's aviation watchdog has warned it's only a matter of time before organized drone attacks bring UK airports to a standstill.…

Categories: News

China hates crypto and scams, but is now outraged USA acquired bitcoin from a scammer

The Register - Wed, 12/11/2025 - 04:47
A new theory from the agency that brought us ‘America hacked itself to blame Beijing’

China’s National Computer Virus Emergency Response Center (CVERC) has alleged a nation-state entity, probably the USA, was behind a 2020 attack on a bitcoin mining operation and by doing so has gone into bat for entities that Beijing usually blasts.…

Categories: News

Australia’s spy boss says authoritarian nations ready to commit ‘high-impact sabotage’

The Register - Wed, 12/11/2025 - 01:17
‘Elite teams’ are pondering cyber-attacks to turn off energy supply or telecoms networks

The head of Australia’s Security Intelligence Organisation (ASIO) has warned that authoritarian regimes “are growing more willing to disrupt or destroy critical infrastructure”, using cyber-sabotage.…

Categories: News

North Korean spies turn Google's Find Hub into remote-wipe weapon

The Register - Tue, 11/11/2025 - 16:26
KONNI espionage crew covertly abused Google’s Find My Device feature to remotely factory-reset Android phones

North Korean state-backed spies have found a new way to torch evidence of their own cyber-spying – by hijacking Google's "Find Hub" service to remotely wipe Android phones belonging to their South Korean targets.…

Categories: News

Pages

Subscribe to Sec Tec Limited aggregator - News