The Register
PostHog admits Shai-Hulud 2.0 was its biggest ever security bungle
PostHog says the Shai-Hulud 2.0 npm worm compromise was "the largest and most impactful security incident" it's ever experienced after attackers slipped malicious releases into its JavaScript SDKs and tried to auto-loot developer credentials.…
Brit telco Brsk confirms breach as bidding begins for 230K+ customer records
British telco Brsk is investigating claims that it was attacked by cybercriminals who made off with more than 230,000 files.…
GrapheneOS bails on OVHcloud over France's privacy stance
French cloud outfit OVHcloud took another hit this week after GrapheneOS, a mobile operating system, said it was ditching the company's servers over concerns about France's approach to digital privacy.…
TryHackMe races to add women to Christmas cyber challenge roster after backlash
Cybersecurity training provider TryHackMe is scrambling to recruit women infosec pros to help with its Christmas challenge following backlash concerning a lack of gender diversity.…
OBR drags in cyber bigwig after Budget leak blunder
The Office for Budget Responsibility (OBR) has drafted in former National Cyber Security Centre (NCSC) chief Ciaran Martin to sniff out how its Budget day forecast wandered onto the open internet before the Chancellor had even reached the dispatch box.…
UK digital ID plan gets a price tag at last – £1.8B
The UK government has finally put a £1.8 billion price tag on its digital ID plans – days after the minister responsible refused to name a figure.…
Korean web giant Naver acquired crypto exchange Upbit, which reported a $30m heist a day later
South Korean web giant Naver has had an interesting week, after it acquired a cryptocurrency exchange that the next day revealed it had suffered a serious cyberattack.…
Zendesk users targeted as Scattered Lapsus$ Hunters spin up fake support sites
Scattered Lapsus$ Hunters may be circling Zendesk users for its latest extortion campaign, with new phishing domains and weaponized helpdesk tickets uncovered by ReliaQuest.…
OpenAI cuts off Mixpanel after analytics leak exposes API users
OpenAI says API users may be affected by a recent breach at its former data analytics provider, Mixpanel.…
FCC sounds alarm after emergency tones turned into potty-mouthed radio takeover
Malicious intruders have hijacked US radio gear to turn emergency broadcast tones into a profanity-laced alarm system.…
Asahi admits ransomware gang may have spilled almost 2M people's data
Asahi has finally done the sums on September's ransomware attack in Japan, conceding the crooks may have helped themselves to personal data tied to almost 2 million people.…
Scottish council still rebuilding systems two years after ransomware attack
Auditors remain concerned about the cyber resilience of a Scottish council as some systems are yet to be fully rebuilt following a ransomware attack in November 2023.…
Gainsight CEO downplays breach, says only a 'handful' of customers had data stolen
Gainsight CEO Chuck Ganapathi downplayed the victim count related to his company's recent breach, saying he's only aware of "a handful of customers" who had their data affected after Salesforce flagged unusual activity involving Gainsight's connected app.…
Botnet takes advantage of AWS outage to smack 28 countries
A Mirai-based botnet named ShadowV2 emerged during last October's widespread AWS outage, infecting IoT devices across industries and continents, likely serving as a "test run" for future attacks, according to Fortinet's FortiGuard Labs.…
Mobile industry warns patchwork cyber regs are driving up costs
Mobile operators' core cybersecurity spending is projected to more than double by 2030 as threats evolve, while poorly designed and fragmented policy frameworks add extra compliance costs, according to industry group the GSMA.…
CodeRED emergency alert system CodeDEAD after INC ransomware attack
Towns and cities across the US are without access to their CodeRED emergency alert system following a cyberattack on vendor Crisis24.…
US Navy scuttles Constellation frigate program for being too slow for tomorrow's threats
The US Navy is scrapping an entire shipbuilding program in an effort to find alternatives that can be delivered faster to counter expected threats.…
London councils probe cyber incident as shared IT systems knocked offline
Two London councils are scrambling for answers after declaring a cybersecurity issue that began on Monday.…
Top five cybersecurity Black Friday deals for businesses 2025
Partner Content The annual Black Friday scramble isn't just for consumers elbowing each other for discounted tellies. For IT directors and CISOs, it's become a strategic procurement window. That narrow slice of the year when security budgets suddenly stretch further, and solutions that were under consideration can finally get approved.…
Lifetime access to AI-for-evil WormGPT 4 costs just $220
Attackers don't need to trick ChatGPT or Claude Code into writing malware or stealing data. There's a whole class of LLMs built especially for the job.…