News

Apple slips up on ChillyHell macOS malware, lets it past security . . . for 4 years

The Register - Wed, 10/09/2025 - 20:06
'We do believe that this was likely the creation of a cybercrime group,' threat hunter tells The Reg

ChillyHell, a modular macOS backdoor believed to be long dormant, has likely been infecting computers for years while flying under the radar, according to security researchers who spotted a malware sample uploaded to VirusTotal in May.…

Categories: News

Jaguar Land Rover U-turns to confirm 'some data' affected after cyber prang

The Register - Wed, 10/09/2025 - 17:05
Systems offline as specialists continue to comb through wreckage

Jaguar Land Rover (JLR) says "some data" was affected after the luxury car maker suffered a digital break-in early last week.…

Categories: News

Uncle Sam indicts alleged ransomware kingpin tied to $18B in damages

The Register - Wed, 10/09/2025 - 12:30
Prosecutors claim Ukrainian ran LockerGoga, MegaCortex, and Nefilim ops – $11M bounty on his head

A Ukrainian national faces serious federal charges and an $11 million bounty after allegedly orchestrating ransomware operations that caused an estimated $18 billion in damages across hundreds of organizations worldwide.…

Categories: News

Flu jab email mishap exposes hundreds of students' personal data

The Register - Wed, 10/09/2025 - 11:13
One parent expressed concern for their child's safety

A clumsy data breach has affected hundreds of children at a Birmingham secondary school.…

Categories: News

Cybercrooks ripped the wheels off at Jaguar Land Rover. Here's how not to get taken for a ride

The Register - Wed, 10/09/2025 - 09:00
Are you sure you know who has access to your systems?

Feature  Jaguar Land Rover (JLR) is the latest UK household name to fall victim to a major cyberattack. IT systems across multiple sites have been offline for over a week after what the company described as a "severe disruption."…

Categories: News

This Patch Tuesday, SAP is the worst offender and Microsoft users can kinda chill

The Register - Wed, 10/09/2025 - 04:31
ERP giant patches flaw that allows total takeover of NetWeaver, Microsoft has nothing under attack for once

September’s Patch Tuesday won’t require Microsoft users to rapidly repair rancid software, but SAP users need to move fast to address extremely dangerous bugs.…

Categories: News

More packages poisoned in npm attack, but would-be crypto thieves left pocket change

The Register - Tue, 09/09/2025 - 22:41
Miscreants cost victims time rather than money

During the two-hour window on Monday in which hijacked npm versions were available for download, malware-laced packages reached one in 10 cloud environments, according to Wiz researchers. But crypto-craving crims did little more than annoy defenders.…

Categories: News

New cybersecurity rules land for Defense Department contractors

The Register - Tue, 09/09/2025 - 21:06
Now if only someone would remember to apply those rules inside the DoD

It's about to get a lot harder for private companies that are lax on cybersecurity to get a contract with the Pentagon, as the Defense Department has finalized a rule requiring contractor compliance with its Cybersecurity Maturity Model Certification (CMMC) program.…

Categories: News

Defense Dept didn't protect social media accounts, left stream keys out in public

The Register - Tue, 09/09/2025 - 18:53
'The practice… has since been fixed,' Pentagon official tells The Reg

The US Department of Defense, up until this week, routinely left its social media accounts wide open to hijackers via stream keys - unique, confidential identifiers generated by streaming platforms for broadcasting content. If exposed, these keys can allow attackers to output anything they want from someone else's channel.…

Categories: News

No gains, just pains as 1.6M fitness phone call recordings exposed online

The Register - Tue, 09/09/2025 - 18:00
HelloGym's data security clearly skipped leg day

Exclusive  Sensitive info from hundreds of thousands of gym customers and staff – including names, financial details, and potentially biometric data in the form of audio recordings – was left sitting in an unencrypted, non-password protected database, according to a security researcher who shut it down.…

Categories: News

What the Plex? Streaming service suffers yet another password spill

The Register - Tue, 09/09/2025 - 14:45
For the third time in a decade

Streaming platform Plex is warning some users to reset their passwords after suffering yet another breach.…

Categories: News

Nokia successor HMD spawns secure device biz with Euro-made smartphone

The Register - Tue, 09/09/2025 - 11:15
Ivalo XE handset targets governments and security critical sectors, though Qualcomm silicon keeps it tied to the US

Finnish phone maker HMD Global is launching a business unit called HMD Secure to target governments and other security-critical customers, and has its first device ready to go.…

Categories: News

Anthropic's Claude Code runs code to test if it is safe – which might be a big mistake

The Register - Tue, 09/09/2025 - 10:30
AI security reviews add new risks, say researchers

App security outfit Checkmarx says automated reviews in Anthropic's Claude Code can catch some bugs but miss others – and sometimes create new risks by executing code while testing it.…

Categories: News

UK toughens Online Safety Act with ban on self-harm content

The Register - Tue, 09/09/2025 - 07:29
Charities welcome change, but critics warn the law is already too broad

Tech companies will be legally required to prevent content involving self-harm from appearing on their platforms – rather than responding and removing it – in a planned amendment to the UK's controversial Online Safety Act.…

Categories: News

Forget disappearing messages – now Signal will store 100MB of them for you for free

The Register - Tue, 09/09/2025 - 04:33
Including messages sent to users, a potential problem for the privacy-conscious

Encrypted messaging app Signal is rolling out a free storage system for its users, with extra space if folks are willing to pay for it.…

Categories: News

WhatsApp's former security boss claims reporting infosec failings led to ousting

The Register - Tue, 09/09/2025 - 00:36
Meta shrugs off allegations of improper dismissal, ignoring privacy and security

WhatsApp's former head of security, Attaullah Baig, has filed a lawsuit against its parent company, Meta, alleging that the social media megalith retaliated against him for reporting security failings that violated legal commitments.…

Categories: News

The US government has no idea how many cybersecurity pros it employs

The Register - Mon, 08/09/2025 - 22:02
Auditors find federal cybersecurity workforce data messy, incomplete, and unreliable

The US federal government employs tens of thousands of cybersecurity professionals at a cost of billions per year – or at least it thinks it does, as auditors have found the figures are incomplete and unreliable. …

Categories: News

Drift massive attack traced back to loose Salesloft GitHub account

The Register - Mon, 08/09/2025 - 20:52
Meanwhile the victim count grows

The Salesloft Drift breach that compromised "hundreds" of companies including Google, Palo Alto Networks, and Cloudflare, all started with miscreants gaining access to the Salesloft GitHub account in March.…

Categories: News

Dev snared in crypto phishing net, 18 npm packages compromised

The Register - Mon, 08/09/2025 - 20:06
Popular npm packages debug, chalk, and others hijacked in massive supply chain attack

Crims have added backdoors to at least 18 npm packages after developer Josh Junon inadvertently authorized a reset of the two-factor authentication protecting his npm account.…

Categories: News

Salt Typhoon used dozens of domains, going back five years. Did you visit one?

The Register - Mon, 08/09/2025 - 18:47
Plus ties to the Chinese spies who hacked Barracuda email gateways

Security researchers have uncovered dozens of domains used by Chinese espionage crew Salt Typhoon to gain stealthy, long-term access to victim organizations going back as far as 2020.…

Categories: News

Pages

Subscribe to Sec Tec Limited aggregator - News