News

Ivanti EPMM holes let miscreants plant shady listeners, CISA says

The Register - Fri, 19/09/2025 - 18:23
Unnamed org compromised with two malware sets

An unknown attacker has abused a couple of flaws in Ivanti Endpoint Manager Mobile (EPMM) and deployed two sets of malware against an unnamed organization, according to the US Cybersecurity and Infrastructure Security Agency.…

Categories: News

Ding ding: Fortra rings the perfect-10 bell over latest GoAnywhere MFT bug

The Register - Fri, 19/09/2025 - 15:30
Outside experts say the vulnerability has probably already been exploited

Budding ransomware crooks have another shot at exploiting Fortra's GoAnywhere MFT product now that a new 10/10 severity vulnerability needs patching.…

Categories: News

Scattered Spider teen cuffed after buying games and meals with extortion bitcoin

The Register - Fri, 19/09/2025 - 14:02
Bad opsec

Thalha Jubair, one of the two UK teens arrested on Tuesday and accused of being members of the notorious Scattered Spider cybercrime gang, allegedly played a role in bilking more than 100 organizations out of at least $115 million in ransom payments. The cops nabbed him after following a number of clues, including paying for gift cards from a wallet on the same server that also held wallets receiving extortion payments.…

Categories: News

One token to pwn them all: Entra ID bug could have granted access to every tenant

The Register - Fri, 19/09/2025 - 13:30
Until Microsoft lobbed it into a virtual volcano

A security researcher claims to have found a flaw that could have handed him the keys to almost every Entra ID tenant worldwide.…

Categories: News

OpenAI plugs ShadowLeak bug in ChatGPT that let miscreants raid inboxes

The Register - Fri, 19/09/2025 - 11:30
Radware says flaw enabled hidden email prompts to trick Deep Research agent into exfiltrating sensitive data

ChatGPT's research assistant sprung a leak – since patched – that let attackers steal Gmail secrets with just a single carefully crafted email.…

Categories: News

Charities warn Ofcom too soft on Online Safety Act violators

The Register - Fri, 19/09/2025 - 11:00
Another blow for the legislation as Parliament continues to hear stakeholder views

As UK ministers continue to quiz stakeholders over the effectiveness of the Online Safety Act, one charity chief raised concerns over the robustness of Ofcom's enforcement of the controversial legislation.…

Categories: News

MI6 reveals 'Silent Courier' dark web portal upgrade it hopes will help it recruit new spies

The Register - Fri, 19/09/2025 - 07:27
YouTube vids explain digital tradecraft to reach spooks over Tor or VPN without blowing your cover

The UK’s Secret Intelligence Service, aka MI6, has created a dark web portal called “Silent Courier” that it hopes would-be foreign informants will find a suitably secure means of sharing secrets.…

Categories: News

Google pushes emergency patch for Chrome 0-day - check your browser version now

The Register - Thu, 18/09/2025 - 19:17
Sixth such Chrome flaw this year spotted by the Chocolate Factory, already in play

Google pushed an emergency patch for a high-severity Chrome flaw, already under active exploitation. So it's time to make sure you're running the most recent version of the web browser.…

Categories: News

Crims bust through SonicWall to grab sensitive config data

The Register - Thu, 18/09/2025 - 17:15
Vendor pulls plug on cloud backup feature, urges admins to reset passwords and re-secure devices

SonicWall is telling some customers to reset passwords after attackers broke into its cloud backup service and accessed firewall configuration data.…

Categories: News

Cybercriminals pwn 850k+ Americans' healthcare data

The Register - Thu, 18/09/2025 - 16:04
Three US medical centers fess up to serious breaches

Cybercriminals broke in and stole nearly a million Americans' data in the space of a week, in the course of three digital burglaries at healthcare providers.…

Categories: News

Two 'Scattered Spider' teens charged over attack on London’s transport network

The Register - Thu, 18/09/2025 - 14:00
Decisive action comes nearly a year after the attack and first arrest took place

Two teenagers are set to appear in court today after being charged with offences related to the cyberattack on Transport for London (TfL) in August 2024.…

Categories: News

Cloudflare DDoSed itself with React useEffect hook blunder

The Register - Thu, 18/09/2025 - 13:38
Dashboard loop caused API outage that was hard to troubleshoot

Cloudflare has confessed to a coding error using a React useEffect hook, notorious for being problematic if not handled carefully, that caused an outage for the platform's dashboard and many of its APIs.…

Categories: News

Insight Partners confirms ransomware hit, more than 12,000 caught in data dragnet

The Register - Thu, 18/09/2025 - 12:25
VC giant rebuilt boxes, patched holes, and says it’s beefed up security – but won’t say who did it

Venture capital giant Insight Partners has confirmed that a January ransomware attack compromised the personal data of more than 12,000 people, including employees, former staff, and the firm's usually-secretive limited partners.…

Categories: News

Panda-monium: China-backed cyber crew spoof Congressman to dig for dirt on US trade talks

The Register - Thu, 18/09/2025 - 11:30
Proofpoint spots efforts to spy on US economic policy nerds

Chinese state-aligned online attackers are back at it, targeting US trade policy wonks as Washington and Beijing spar over economic ties.…

Categories: News

Russian fake-news network, led by an ex-Florida sheriff's deputy, storms back into action with 200+ new sites

The Register - Thu, 18/09/2025 - 01:00
As the Trump administration guts efforts to counter election disinfo

The Russian troll farm that in the lead-up to the 2024 US presidential election posted a bizarro video claiming Democratic candidate Kamala Harris was a rhino poacher, is back with hundreds of new fake news websites serving up phony political commentary with an AI assist.…

Categories: News

Scattered Spider gang feigns retirement, breaks into bank instead

The Register - Wed, 17/09/2025 - 19:37
You didn't really trust the crims to keep their word, did you?

Spiders don't change their stripes. Despite gang members' recent retirement claims, Scattered Spider hasn't exited the cybercrime business and instead has shifted focus to the financial sector, with a recent digital intrusion at a US bank.…

Categories: News

Axiom Space aims for orbit with its Orbital Data Center Node

The Register - Wed, 17/09/2025 - 15:51
But will the International Space Station still be there to host its node?

Axiom Space and Spacebilt have announced plans to add optically interconnected Orbital Data Center (ODC) infrastructure to the International Space Station (ISS).…

Categories: News

BreachForums kingpin goes from walk-free deal to 3-year stretch

The Register - Wed, 17/09/2025 - 13:40
Prosecutors say Conor Fitzpatrick's crimes caused 'incalculable' damage

The founder of the popular cybercrime website BreachForums will spend three years in prison after previously being let off with a slap on the wrist.…

Categories: News

UK telco Colt’s recovery from August cyberattack pushes into November

The Register - Wed, 17/09/2025 - 12:45
Pentesters confirm key system is safe but core products remain unavailable

Brit telco Colt Technology Services says its recovery from an August cyberattack might not be completed until late November.…

Categories: News

UEFI Secure Boot for Linux Arm64 – where do we stand?

The Register - Wed, 17/09/2025 - 08:15
Still exotic for now, but moves are afoot

Arm devices are everywhere today and many of them run Linux. The operating system also powers cloud computing and IT environments all over the world. However, x86 is still the dominant architecture of global computer hardware, where the Unified Extensible Firmware Interface (UEFI) with Secure Boot incorporated is a standard. But what does UEFI look like from an Arm perspective?…

Categories: News

Pages

Subscribe to Sec Tec Limited aggregator - News