News

Ex-CISA officials, CISOs dispel 'hacklore,' spread cybersecurity truths

The Register - Mon, 24/11/2025 - 20:01
Don't believe everything you read

Afraid of connecting to public Wi-Fi? Terrified to turn your Bluetooth on? You may be falling for "hacklore," tall tales about cybersecurity that distract you from real dangers. Dozens of chief security officers and ex-CISA officials have launched an effort and website to dispel these myths and show you how not to get hacked for real.…

Categories: News

Years-old bugs in open source tool left every major cloud open to disruption

The Register - Mon, 24/11/2025 - 15:23
Fluent Bit has 15B+ deployments … and 5 newly assigned CVEs

A series of "trivial-to-exploit" vulnerabilities in Fluent Bit, an open source log collection tool that runs in every major cloud and AI lab, was left open for years, giving attackers an exploit chain to completely disrupt cloud services and alter data.…

Categories: News

Intrusion at real estate finance biz sparks concern for big banks

The Register - Mon, 24/11/2025 - 14:46
SitusAMC rules out ransomware, but accounting records for major institutions potentially affected

Real estate finance business SitusAMC says thieves sneaked into its systems earlier this month and made off with confidential client data.…

Categories: News

Shai-Hulud worm returns, belches secrets to 25K GitHub repos

The Register - Mon, 24/11/2025 - 14:08
Trojanized npm packages spread new variant that executes in pre-install phase, hitting thousands within days

A self-propagating malware targeting node package managers (npm) is back for a second round, according to Wiz researchers who say that more than 25,000 developers had their secrets compromised within three days.…

Categories: News

FCC guts post-Salt Typhoon telco rules despite ongoing espionage risk

The Register - Mon, 24/11/2025 - 13:14
Months after China-linked spies burrowed into US networks, regulator tears up its own response

The Federal Communications Commission (FCC) has scrapped a set of telecom cybersecurity rules introduced after the Salt Typhoon espionage campaign, reversing course on measures designed to stop state-backed snoops from slipping back into America's networks.…

Categories: News

CISA orders feds to patch Oracle Identity Manager zero-day after signs of abuse

The Register - Mon, 24/11/2025 - 11:45
Agencies have until December 12 to mitigate flaw that was likely exploited before Big Red released fix

CISA has ordered US federal agencies to patch against an actively exploited Oracle Identity Manager (OIM) flaw within three weeks – a scramble made more urgent by evidence that attackers may have been abusing the bug months before a fix was released.…

Categories: News

Championing cyber security: the national UK cyber team's journey at the European Cyber Security Challenge

The Register - Mon, 24/11/2025 - 09:00
Reflections on coaching, collaboration, and the pursuit of excellence in cyber security

Partner Content  From 6th to 10th October 2025, ten exceptional cyber enthusiasts proudly flew the flag for the United Kingdom in the European Cyber Security Challenge (ECSC), held this year in the vibrant setting of Poland.…

Categories: News

Cryptology boffins’ association to re-run election after losing encryption key needed to count votes

The Register - Mon, 24/11/2025 - 05:43
The shoemaker’s children have new friends

The International Association for Cryptologic Research will run a second election for new board members and other officers, after it was unable to complete its first poll due to a lost encryption key.…

Categories: News

70-hour work weeks no longer enough for Infosys founder, who praises China’s 996 culture

The Register - Mon, 24/11/2025 - 01:16
PLUS: Manga publishers win Cloudflare copyright case; India, EU to link payment systems; Storm over Australia’s weather website; And more!

Asia In Brief  Infosys co-founder Narayana Murthy has suggested Indian citizens should work even longer, suggesting his previous target of 70-hour weeks could climb to 72.…

Categories: News

Weaponized file name flaw makes updating glob an urgent job

The Register - Sun, 23/11/2025 - 22:46
PLUS: CISA issues drone warning; China-linked DNS-hijacking malware; Prison for BTC Samourai; And more

Infosec In Brief  Researchers have urged users of the glob file pattern matching library to update their installations, after discovery of a years-old remote code execution flaw in the tool's CLI.…

Categories: News

ShinyHunters 'does not like Salesforce at all,' claims the crew accessed Gainsight 3 months ago

The Register - Fri, 21/11/2025 - 19:25
'I have compromised other known OAuth apps,' Shiny tells The Reg

EXCLUSIVE  ShinyHunters has claimed responsibility for the Gainsight breach that allowed the data thieves to snarf data from hundreds more Salesforce customers.…

Categories: News

Pages

Subscribe to Sec Tec Limited aggregator - News