The Register

Subscribe to The Register feed
Biting the hand that feeds IT — Enterprise Technology News and Analysis
Updated: 1 hour 22 min ago

Snyk appears to deploy 'malicious' packages targeting Cursor for unknown reason

Tue, 14/01/2025 - 13:13
Packages removed, vendor said to have apologized to AI code editor as onlookers say it could have been a test

Developer security company Snyk is at the center of allegations concerning the possible targeting or testing of Cursor, an AI code editor company, using "malicious" packages uploaded to NPM.…

Categories: News

It's not just Big Tech: The UK's Online Safety Act applies across the board

Tue, 14/01/2025 - 12:15
That niche forum running for 20 years – get ready, there's work to do

Analysis  A little more than two months out from its first legal deadline, the UK’s Online Safety Act is causing concern among smaller online forums caught within its reach. The legislation, which came into law in the autumn of 2023, applies to search services and services that allow users to post content online or to interact with each other.…

Categories: News

UK floats ransomware payout ban for public sector

Tue, 14/01/2025 - 11:04
Stronger proposals may also see private sector applying for a payment 'license'

A total ban on ransomware payments across the public sector might actually happen after the UK government opened a consultation on how to combat the trend of criminals locking up whole systems and taxpayers footing the bill.…

Categories: News

Miscreants 'mass exploited' Fortinet firewalls, 'highly probable' zero-day used

Tue, 14/01/2025 - 01:43
Ransomware 'not off the table,' Arctic Wolf threat hunter tells El Reg

Miscreants running a "mass exploitation campaign" against Fortinet firewalls, which peaked in December, may be using an unpatched zero-day vulnerability to compromise the equipment, according to security researchers who say they've observed the intrusions.…

Categories: News

Cryptojacking, backdoors abound as fiends abuse Aviatrix Controller bug

Mon, 13/01/2025 - 21:00
This is what happens when you publish PoCs immediately, hm?

"Several cloud deployments" are already compromised following the disclosure of the maximum-severity vulnerability in Aviatrix Controller, researchers say.…

Categories: News

Microsoft sues 'foreign-based' cyber-crooks, seizes sites used to abuse AI

Mon, 13/01/2025 - 19:00
Scumbags stole API keys, then started a hacking-as-a-service biz, it is claimed

Microsoft has sued a group of unnamed cybercriminals who developed tools to bypass safety guardrails in its generative AI tools. The tools were used to create harmful content, and access to the tools were sold as a service to other miscreants.…

Categories: News

Azure, Microsoft 365 MFA outage locks out users across regions

Mon, 13/01/2025 - 17:55
It's fixed, mostly, after Europeans had a manic Monday

Microsoft's multi-factor authentication (MFA) for Azure and Microsoft 365 (M365) was offline for four hours during Monday's busy start for European subscribers.…

Categories: News

NATO's newest member comes out swinging following latest Baltic Sea cable attack

Mon, 13/01/2025 - 16:47
'Sweden has changed,' PM warns as trio of warships join defense efforts

Sweden has committed to sending naval forces into the Baltic Sea following yet another suspected Russian attack on underwater cables in the region.…

Categories: News

Ransomware crew abuses AWS native encryption, sets data-destruct timer for 7 days

Mon, 13/01/2025 - 14:00
'Codefinger' crims on the hunt for compromised keys

A new ransomware crew dubbed Codefinger targets AWS S3 buckets and uses the cloud giant's own server-side encryption with customer provided keys (SSE-C) to lock up victims' data before demanding a ransom payment for the symmetric AES-256 keys required to decrypt it.…

Categories: News

Nominet probes network intrusion linked to Ivanti zero-day exploit

Mon, 13/01/2025 - 10:29
Unauthorized activity detected, but no backdoors found

UK domain registry Nominet is investigating a potential intrusion into its network related to the latest Ivanti zero-day exploits.…

Categories: News

Europe coughs up €400 to punter after breaking its own GDPR data protection rules

Mon, 13/01/2025 - 05:27
PLUS: Data broker leak reveals extent of info trading; Hot new ransomware gang might be all AI, no bark; and more

Infosec in brief  Gravy Analytics, a vendor of location intelligence info for marketers which reached a settlement with US authorities last year over its alleged unlawful sale of location, has reportedly been hacked – potentially exposing millions of smartphone users.…

Categories: News

Chinese cyber-spies peek over shoulder of officials probing real-estate deals near American military bases

Fri, 10/01/2025 - 21:45
Gee, wonder why Beijing is so keen on the – checks notes – Committee on Foreign Investment in the US

Chinese cyber-spies who broke into the US Treasury Department also stole documents from officials investigating real-estate sales near American military bases, it's reported.…

Categories: News

Drug addiction treatment service admits attackers stole sensitive patient data

Fri, 10/01/2025 - 15:37
Details of afflictions and care plastered online

BayMark Health Services, one of the biggest drug addiction treatment facilities in the US, says it is notifying some patients this week that their sensitive personal information was stolen.…

Categories: News

Devs sent into security panic by 'feature that was helpful … until it wasn't'

Fri, 10/01/2025 - 08:30
Screenshot showed it wasn't a possible attack – unless you qualify everything Google does as a threat

On Call  Velkomin, Vælkomin, Hoş geldin, and welcome to Friday, and therefore to another edition of On Call – The Register's end-of-week celebration of the tech support tasks you managed to tackle without too much trauma.…

Categories: News

Look for the label: White House rolls out 'Cyber Trust Mark' for smart devices

Thu, 09/01/2025 - 21:45
Beware the IoT that doesn’t get a security tag

The White House this week introduced a voluntary cybersecurity labeling program for technology products so that consumers can have some assurance their smart devices aren't spying on them.…

Categories: News

Zero-day exploits plague Ivanti Connect Secure appliances for second year running

Thu, 09/01/2025 - 14:45
Factory resets and apply patches is the advice amid fortnight delay for other appliances

The cybersecurity industry is urging those in charge of defending their orgs to take mitigation efforts "seriously" as Ivanti battles two dangerous new vulnerabilities, one of which was already being exploited as a zero-day.…

Categories: News

Security pros baited with fake Windows LDAP exploit traps

Thu, 09/01/2025 - 13:16
Tricky attackers trying yet again to deceive the good guys on home territory

Security researchers are once again being lured into traps by attackers, this time with fake exploits of serious Microsoft security flaws.…

Categories: News

Japanese Police claim China ran five-year cyberattack campaign targeting local orgs

Thu, 09/01/2025 - 03:56
‘MirrorFace’ group found ways to run malware in the Windows sandbox, which is worrying

Japan’s National Police Agency and Center of Incident Readiness and Strategy for Cybersecurity have confirmed third party reports of attacks on local orgs by publishing details of a years-long series of attacks attributed to a China-backed source.…

Categories: News

Database tables of student, teacher info stolen from PowerSchool in cyberattack

Thu, 09/01/2025 - 00:44
Class act: Biz only serves 60M people across America, no biggie

A leading education software maker has admitted its IT environment was compromised in a cyberattack, with students and teachers' personal data – including some Social Security Numbers and medical info – stolen.…

Categories: News

I tried hard, but didn't fix all of cybersecurity, admits outgoing US National Cyber Director

Wed, 08/01/2025 - 23:56
In colossal surprise, ONCD boss Harry Coker says more work is needed

The outgoing leader of the United States' Office of the National Cyber Director has a clear message for whomever President-elect Trump picks to be his successor: There's a lot of work still to do.…

Categories: News

Pages