The Register
China-linked group abuses Fortinet 0-day with post-exploit VPN-credential stealer
Chinese government-linked snoops are exploiting a zero-day bug in Fortinet's Windows VPN client to steal credentials and other information, according to memory forensics outfit Volexity.…
Russian suspected Phobos ransomware admin extradited to US over $16M extortion
A Russian citizen has been extradited from South Korea to the United States to face charges related to his alleged role in the Phobos ransomware operation.…
America's drinking water systems have a hard-to-swallow cybersecurity problem
Nearly a third of US residents are served by drinking water systems with cybersecurity shortcomings, the Environmental Protection Agency's Office of Inspector General found in a recent study – and the agency lacks its own system to track potential attacks. …
Palo Alto Networks tackles firewall-busting zero-days with critical patches
Palo Alto Networks (PAN) finally released a CVE identifier and patch for the zero-day exploit that caused such a fuss last week.…
Navigating third-party risks
Webinar As organizations increasingly rely on third-party contractors, vendors, and service providers, the security risks associated with third-party access can become a top priority.…
Crook breaks into AI biz, points $250K wire payment at their own account
A Maryland AI company has confirmed to the Securities and Exchange Commission (SEC) that it lost $250,000 to a misdirected wire payment.…
Join in the festive cybersecurity fun
Sponsored Post Are you ready to pit your wits against the cyber exercises featured in the Holiday Hack Challenge 2024: Snow-maggedon?…
iOS 18 added secret and smart security feature that reboots iThings after three days
Apple's latest mobile operating system, iOS 18, appears to have added an undocumented security feature that reboots devices if they’re not used for 72 hours.…
Ford 'actively investigating' after employee data allegedly parked on leak site
Ford Motor Company says it is looking into allegations of a data breach after attackers claimed to have stolen an internal database containing 44,000 customer records and dumped the info on a cyber crime souk for anyone to "enjoy."…
Critical 9.8-rated VMware vCenter RCE bug exploited after patch fumble
Two VMware vCenter server bugs, including a critical heap-overflow vulnerability that leads to remote code execution (RCE), have been exploited in attacks after Broadcom’s first attempt to fix the flaws fell short.…
T-Mobile US 'monitoring' China's 'industry-wide attack' amid fresh security breach fears
T-Mobile US said it is "monitoring" an "industry-wide" cyber-espionage campaign against American networks – amid fears Chinese government-backed spies compromised the un-carrier among with various other telecommunications providers.…
Sweden's 'Doomsday Prep for Dummies' guide hits mailboxes today
Residents of Sweden are to receive a handy new guide this week that details how to prepare for various types of crisis situations or wartime should geopolitical events threaten the country.…
Deepen your knowledge of Linux security
Event The security landscape is constantly shifting. If you're running Linux, staying ahead may rely on understanding the challenges - and opportunities - unique to Linux environments.…
Teen serial swatter-for-hire busted, pleads guilty, could face 20 years
Infosec in brief A teenager has pleaded guilty to calling in more than 375 fake threats to law enforcement, and now faces years in prison.…
Will passkeys ever replace passwords? Can they?
Systems Approach I have been playing around with passkeys, or as they are formally known, discoverable credentials.…
Rust haters, unite! Fil-C aims to Make C Great Again
Developers looking to continue working in the C and C++ programming languages amid the global push to promote memory-safe programming now have another option that doesn't involve learning Rust.…
Swiss cheesed off as postal service used to spread malware
Switzerland's National Cyber Security Centre (NCSC) has issued an alert about malware being spread via the country's postal service.…
Bloke behind Helix Bitcoin launderette jailed for three years, hands over $400M
An Ohio man, who operated the Grams dark-web search engine and the Helix cryptocurrency money-laundering service associated with it, has been sentenced to three years in prison.…
Letting chatbots run robots ends as badly as you'd expect
Science fiction author Isaac Asimov proposed three laws of robotics, and you'd never know it from the behavior of today's robots or those making them.…
Mystery Palo Alto Networks hijack-my-firewall zero-day now officially under exploit
A critical zero-day vulnerability in Palo Alto Networks' firewall management interface that can allow an unauthenticated attacker to remotely execute code is now officially under active exploitation.…