News
Penn State pays DoJ $1.25M to settle cybersecurity compliance case
Pennsylvania State University has agreed to pay the Justice Department $1.25 million to settle claims of misrepresenting its cybersecurity compliance to the federal government and leaving sensitive data improperly secured. …
Warning! FortiManager critical vulnerability under active attack
Fortinet has gone public with news of a critical flaw in its software management platform.…
'Satanic' data thief claims to have slipped into 350M Hot Topic shoppers info
A data thief calling themselves Satanic claims to have purloined the records of around 350 million customers of fashion retailer Hot Topic.…
Microsoft SharePoint RCE flaw exploits in the wild – you've had 3 months to patch
A Microsoft SharePoint bug that can allow an attacker to remotely inject code into vulnerable versions is under active exploitation, according to the US Cybersecurity and Infrastructure Security Agency (CISA).…
Millions of Android and iOS users at risk from hardcoded creds in popular apps
An analysis of widely used mobile apps offered on Google Play and the Apple App Store has found hardcoded and unencrypted cloud service credentials, exposing millions of users to major security problems.…
US lawmakers push DoJ to prosecute tax prep firms for leaking taxpayer data to big tech
A quartet of lawmakers have penned a letter to the Department of Justice asking it to prosecute tax preparation companies for sharing customer data, including tax return information, with Meta and Google.…
TSMC blows whistle on potential sanctions-busting shenanigans from Huawei
TSMC has reportedly tipped off US officials to a potential attempt by Huawei to circumvent export controls and obtain AI chips manufactured by the Taiwanese company.…
VMware fixes critical RCE, make-me-root bugs in vCenter - for the second time
VMware has pushed a second patch for a critical, heap-overflow bug in the vCenter Server that could allow a remote attacker to fully compromise vulnerable systems after the first software update, issued last month, didn't work.…
Tech firms to pay millions in SEC penalties for misleading SolarWinds disclosures
Four high-profile tech companies reached an agreement with the Securities and Exchange Commission to pay millions of dollars in penalties for misleading investors about their exposure to the 2020 SolarWinds hack.…
Akira ransomware is encrypting victims again following pure extortion fling
Experts believe the Akira ransomware operation is up to its old tricks again, encrypting victims' files after a break from the typical double extortion tactics.…
Pixel perfect Ghostpulse malware loader hides inside PNG image files
The Ghostpulse malware strain now retrieves its main payload via a PNG image file's pixels. This development, security experts say, is "one of the most significant changes" made by the crooks behind it since launching in 2023.…
China’s Spamouflage cranks up trolling of US Senator Rubio as election day looms
China's Spamouflage disinformation crew has been targeting US Senator Marco Rubio (R-Florida) with its fake news campaigns over the past couple of months, trolling the Republican lawmaker's official X account and posting negative stories about Rubio on Reddit and Medium.…
Sophos to snatch Secureworks in $859M buyout: Why fight when you can just buy?
British security biz Sophos has announced a plan to gobble up competitor Secureworks in an $859 million deal that will make Dell happy.…
The billionaire behind Trump's 'unhackable' phone is on a mission to fight Tesla's FSD
Interview This month, presidential hopeful Donald Trump got a tool in his arsenal, some allegedly "unhackable" communications kit, and The Register has talked to the man behind the operating system, who also ran for the US Senate on a campaign to get self-driving Teslas off the road and is on something of a crusade about the matter.…
Pages
