News

Bot her emails: most modern phishing campaigns are AI-enabled

The Register - Thu, 30/04/2026 - 21:26
KnowBe4 says 86% of phishing it tracked used AI, and inboxes are only the start

Give a man a phishing kit and he might get lucky a couple of times; teach an AI to phish and it'll change the landscape, if KnowBe4's latest phishing trends report is accurate.…

Categories: News

FBI cyber boss: China's hacker-for-hire ecosystem 'out of control'

The Register - Thu, 30/04/2026 - 20:30
One alleged cyber contractor was extradited to the US over the weekend

China's "hacker-for-hire ecosystem has gotten out of control," according to Brett Leatherman, assistant director of the FBI's cyber division.…

Categories: News

Google's fix for critical Gemini CLI bug might break your CI/CD pipelines

The Register - Thu, 30/04/2026 - 18:15
This CVSS 10.0 RCE vuln has been patched, automatically for some, so better check those workflows

If you use Gemini CLI, watch out: Google has patched a CVSS 10.0 vulnerability in its command-line AI tool and is warning anyone running it in headless mode, or through GitHub Actions, to review their workflows.…

Categories: News

French prosecutors link 15-year-old to mega-breach at state’s secure document agency

The Register - Thu, 30/04/2026 - 17:39
Two computer crime allegations follow up to 18M lines of data surfacing online

French prosecutors say police detained a 15-year-old on April 25 over the alleged theft of millions of records from France Titres (ANTS), the agency handling secure documents.…

Categories: News

Nearly half of UK businesses pwned last year as phishing keeps doing the job like it's 2005

The Register - Thu, 30/04/2026 - 12:35
Turns out the real problem is not AI but staff still clicking on dodgy emails from 'IT support'

Nearly half of UK businesses are still getting breached, and in many cases, the attacker's big breakthrough is an employee clicking "sure, why not" on a fake login page.…

Categories: News

What type of 'C2 on a sleep cycle' do they leave behind? Novel Chinese spy group found in critical networks in Poland, Asia

The Register - Thu, 30/04/2026 - 12:00
Just in time for the Trump-Xi summit

Exclusive  A novel China-linked threat group infiltrated more than a dozen critical networks in Poland, Asian countries, and possibly beyond, beginning in December 2024 and with activity uncovered as recently as this month.…

Categories: News

Bug of the year (so far): Nasty cPanel vulnerability probably exploited as a 0-day

The Register - Thu, 30/04/2026 - 11:14
Emergency patches out now for those managing the millions of domains assumed to be affected

Emergency patches are available for a critical vulnerability in cPanel and WHM that allows attackers to bypass authentication and gain root access to servers managed using it.…

Categories: News

Britain's £6B armoured sickener Ajax cleared for duty despite injuring troops

The Register - Thu, 30/04/2026 - 09:45
Investigation finds no single cause for soldiers falling ill, just bad bolts, cold air, and apparently the soldiers themselves

Britain's notorious Ajax armored vehicles are being accepted back from the manufacturer after investigations found no single cause for the symptoms plaguing crews, meaning soldiers will need to grin and bear it.…

Categories: News

Finance company stores DB credentials in helpfully labeled spreadsheet

The Register - Thu, 30/04/2026 - 09:00
Great idea, guys. Let's keep all of the data in an Excel file with weak password protection

PWNED  Welcome, once again, to PWNED, the weekly column where we recount the adventures of IT explorers who found their own pile of quicksand and then jumped right into it. This week's story involves keeping sensitive information in a very vulnerable place and then not protecting it adequately.…

Categories: News

Linux cryptographic code flaw offers fast route to root

The Register - Thu, 30/04/2026 - 01:01
Patches land for authencesn flaw enabling local privilege escalation

Developers of major Linux distributions have begun shipping patches to address a local privilege escalation (LPE) vulnerability arising from a logic flaw.…

Categories: News

Researchers move in the right direction, develop powerful GPS interference alarm

The Register - Wed, 29/04/2026 - 21:11
ORNL says portable detector kit can separate real GPS signals from fake ones even at equal strength

GPS spoofing, which sends fake satellite-like signals, and GPS jamming, which drowns receivers in noise, are increasingly serious problems. Researchers at Oak Ridge National Laboratory in Tennessee have created what they say is the most effective system yet for detecting GPS interference, which could help blunt such attacks.…

Categories: News

Microsoft's patch for a 0-day exploited by Russian spies fell short. Another Windows flaw is under attack

The Register - Wed, 29/04/2026 - 20:15
Second try's a charm?

Microsoft and the US Cybersecurity and Infrastructure Security Agency (CISA) warned that attackers are exploiting a zero-click Windows flaw that can expose sensitive information on vulnerable systems.…

Categories: News

Legacy TLS tour continues with Exchange Online blocking old versions from July 2026

The Register - Wed, 29/04/2026 - 19:35
Microsoft readies the axe once again for yesterday's security

Microsoft has warned users still clinging to legacy TLS versions that the end is nigh for TLS 1.0 and 1.1 on POP3 and IMAP4 connections to Exchange Online.…

Categories: News

CISA flags data-theft bug in NSA-built OT networking tool

The Register - Wed, 29/04/2026 - 16:35
GrassMarlin leaks sensitive information, provided your targeting phishing skills are sharp enough

The Cybersecurity and Infrastructure Security Agency (CISA) is warning anyone who uses GrassMarlin, a tool developed by the National Security Agency (NSA), about a new vulnerability that attackers can use to snoop on sensitive information.…

Categories: News

GitHub: Woah, a genuinely helpful AI-assisted bug report that isn't total slop. Here, Wiz, take this wad of cash

The Register - Wed, 29/04/2026 - 14:02
Claude ploughs through months of work in rapid time, helps Wiz researchers nab lucrative award

Wiz researchers are set for a tidy payday thanks to their discovery of a high-severity flaw in GitHub's git infrastructure that handed remote attackers full read/write access to private GitHub repositories using a single command.…

Categories: News

EU waves through open source age-check tool to keep kids safe online

The Register - Wed, 29/04/2026 - 13:03
'Online platforms can rely on our app,' says Commish, 'there are no more excuses'

The European Commission has recommended EU member states adopt an age verification app designed to protect children from harmful online content.…

Categories: News

GoDaddy customer claims registrar transferred 27-year-old domain without any security checks

The Register - Wed, 29/04/2026 - 11:00
32 phone calls, 17 email chains, a 5-day ordeal, and no help during the daddy of all stuffups, claim those affected

GoDaddy is currently investigating claims that it handed complete control of a valid 27-year-old domain to another customer, without requiring them to pass any authentication processes or upload any supporting documents.…

Categories: News

30 ClawHub skills secretly turn AI agents into a crypto swarm

The Register - Wed, 29/04/2026 - 07:32
Yet another reason not to feast on OpenClaw

Thirty ClawHub skills published by a single author are silently co-opting AI agents and creating a mass cryptocurrency mining swarm – without any malware or user consent.…

Categories: News

Don't pay Vect a ransom - your data's likely already wiped out

The Register - Tue, 28/04/2026 - 19:36
'Full recovery is impossible for anyone, including the attacker'

Organizations hit by the wave of Trivy and LiteLLM supply-chain compromises that paid Vect in hopes of recovering their data likely did not get much back, according to Check Point Research. That's because the ransomware Vect uses isn't actually ransomware at all, but a wiper that destroys any file larger than 128KB.…

Categories: News

Have I Been Pwned claims Pitney Bowes hit by 8.2M email address leak

The Register - Tue, 28/04/2026 - 15:15
Names, phone numbers, physical addresses also included in Shiny Hunters alleged data dump

Logistics technology company Pitney Bowes, which makes franking machines for US postage, is the latest scalp claimed by ShinyHunters and its ongoing spree of pay-or-leak attacks against major organizations.…

Categories: News

Pages

Subscribe to Sec Tec Limited aggregator - News