News

Microsoft stays mum about M365 Copilot on-demand security bypass

The Register - Thu, 21/08/2025 - 00:59
Redmond doesn't bother informing customers about some security fixes

UPDATED  Microsoft has chosen not to tell customers about a recently patched vulnerability in M365 Copilot.…

Categories: News

Amazon quietly fixed Q Developer flaws that made AI agent vulnerable to prompt injection, RCE

The Register - Wed, 20/08/2025 - 22:01
Move along, nothing to see here

Amazon has quietly fixed a couple of security issues in its coding agent: Amazon Q Developer VS Code extension. Attackers could use these vulns to leak secrets, including API keys from a developer's machine, and run arbitrary code.…

Categories: News

FBI: Russian spies exploiting a 7-year-old Cisco bug to slurp configs from critical infrastructure

The Register - Wed, 20/08/2025 - 19:20
Snarfing up config files for 'thousands' of devices…just for giggles, we're sure

The FBI and security researchers today warned that Russian government spies exploited a seven-year-old bug in end-of-life Cisco networking devices to snoop around in American critical infrastructure networks and collect information on industrial systems.…

Categories: News

Commvault releases patches for two nasty bug chains after exploits proven

The Register - Wed, 20/08/2025 - 18:03
Researchers disclosing their findings said 'it's as bad as it sounds'

Researchers at watchTowr just published working proof-of-concept exploits for two unauthenticated remote code execution bug chains in backup giant Commvault.…

Categories: News

'Limited' data leak at Aussie telco turns out to be 280K customer details

The Register - Wed, 20/08/2025 - 17:45
iiNet breach blamed on single stolen login, with emails, phone numbers, and addresses exposed

Aussie telco giant TPG Telecom has opened an investigation after confirming a cyberattack at subsidiary iiNet.…

Categories: News

McDonald's not lovin' it when hacker exposes nuggets of rotten security

The Register - Wed, 20/08/2025 - 08:34
Burger slinger gets a McRibbing, reacts by firing staffer who helped

A white-hat hacker has discovered a series of critical flaws in McDonald's staff and partner portals that allowed anyone to order free food online, get admin rights to the burger slinger's marketing materials, and could allow an attacker to get a corporate email account with which to conduct a little filet-o-phishing.…

Categories: News

Don't want drive-by Ollama attackers snooping on your local chats? Patch now

The Register - Tue, 19/08/2025 - 22:57
Reconfigure local app settings via a 'simple' POST request

A now-patched flaw in popular AI model runner Ollama allows drive-by attacks in which a miscreant uses a malicious website to remotely target people's personal computers, spy on their local chats, and even control the models the victim's app talks to, in extreme cases by serving poisoned models.…

Categories: News

Like burglars closing a door, Apache ActiveMQ attackers patch critical vuln after breaking in

The Register - Tue, 19/08/2025 - 21:28
Intruders hoped no one would notice their presence

Criminals exploiting a critical vulnerability in open source Apache ActiveMQ middleware are fixing the flaw that allowed them access, after establishing persistence on Linux servers.…

Categories: News

Casino tech outfit Bragg cops to intrusion but says data jackpot untouched

The Register - Tue, 19/08/2025 - 16:31
Toronto company says weekend cyber raid hit internal IT, not punters' wallets

Canadian casino software slinger Bragg Gaming Group has disclosed a "cybersecurity incident," though it's adamant the intruders never got their hands on customer data.…

Categories: News

Pages

Subscribe to Sec Tec Limited aggregator - News