News

Jen Easterly, cybersecurity's 'relentless optimist,' hopes feds come back to RSAC next year

The Register - 25 min 7 sec ago
Ex-CISA boss also says no reason to panic about AI and security

RSAC 2026  "Everybody feels massive FOMO if they don't get to RSAC," Jen Easterly says.…

Categories: News

Only Trump can decide when cyberwar turns into real war

The Register - 1 hour 9 min ago
Four former NSA bosses walk onto the stage at RSAC…

rsac 2026  There's a theoretical red line with cyber warfare. Cross it, and the US will respond with a physical attack like missile strikes. And that line "is whatever the President says it is," according to former NSA boss retired General Paul Nakasone.…

Categories: News

Enterprise PCs are unreliable, unpatched, and unloved compared to Macs

The Register - 12 hours 35 min ago
Omnissa telemetry suggests business buyers are loving Apple and Google

End-user compute vendor Omnissa, the company formed by the spin-out of VMware’s virtual desktops, applications, and device management biz, has dug into the telemetry it collects from customers and painted a picture of the world’s enterprise hardware fleet – and the news is better for Google and Apple than it is for Microsoft.…

Categories: News

EFF has a new boss to lead the fight against privacy-sucking forces of doom

The Register - Tue, 24/03/2026 - 21:00
Cyber rights org retools for the days of AI and unrestrained government

interview  The Electronic Frontier Foundation (EFF) on Tuesday appointed Nicole Ozer to succeed Cindy Cohn as the cyber rights group's executive director when Cohn departs this summer.…

Categories: News

1K+ cloud environments infected following Trivy supply chain attack

The Register - Tue, 24/03/2026 - 20:31
Crims 'creating a snowball effect' across open source projects

RSAC 2026  Thousands of organizations' cloud environments have been infected with secret-stealing malware as a result of the Trivy supply-chain attack last week, and now the crims that compromised the open source scanners are working with notorious extortion crews like Lapsus$.…

Categories: News

LiteLLM loses game of Trivy pursuit, gets compromised

The Register - Tue, 24/03/2026 - 19:11
Python interface for LLMs infected with malware via polluted CI/CD pipeline

Two versions of LiteLLM, an open source interface for accessing multiple large language models, have been removed from the Python Package Index (PyPI) following a supply chain attack that injected them with malicious credential-stealing code.…

Categories: News

HackerOne slams supplier for delayed breach notice after staff data exposed

The Register - Tue, 24/03/2026 - 13:27
Nearly 300 employees caught up in intrusion at benefits provider Navia

Almost 300 HackerOne employees are caught up in a data breach, with the bug bounty biz slamming a third-party benefits provider for a weeks-long delay in notification.…

Categories: News

New routers? Made abroad? Yeah, that's going to be a no from Uncle Sam

The Register - Tue, 24/03/2026 - 12:19
Unfortunately, there aren't many options unless you're Starlink

Citing national security fears, America is effectively banning any new consumer-grade network routers made abroad.…

Categories: News

Russian initial access broker who fed ransomware crews gets 81 months in US prison

The Register - Tue, 24/03/2026 - 11:32
Aleksei Volkov sentenced after enabling attacks that cost victims millions

A Russian national who sold the keys to corporate networks faces nearly seven years in a US prison after prosecutors tied his handiwork to a string of ransomware attacks costing victims millions of dollars.…

Categories: News

Claude attacks were 'Rorschach test' for infosec community, scaring former NSA boss

The Register - Mon, 23/03/2026 - 22:50
'It freakin' worked' says Rob Joyce - and shows how relentless AI agents can find holes humans miss

RSAC 2026  The now-infamous Anthropic report about Chinese cyberspies abusing Claude AI to automate cyberattacks was a Rorschach test for the infosec community, according to former NSA cyber boss Rob Joyce.…

Categories: News

Public-private partnerships vital in disrupting China's Typhoons, says RSA panel with no government speakers

The Register - Mon, 23/03/2026 - 21:56
Washington content to be represented by actual empty chairs

RSA 2026  Back in the day (circa 2023) when cybercrime group Scattered Spider and its help-desk voice-phishing calls were a relatively new threat, the feds considered pulling the government's top cyber-threat hunters and their private-sector counterparts into one room to share information, in real time, about this loosely knit extortion ring that was terrorizing enterprises.…

Categories: News

Lightning-fast exploits make it essential to patch fast, ask questions later

The Register - Mon, 23/03/2026 - 20:42
Here's where you ought to spend your security billable hours budget this year

Strengthen your MFA policies, double-down on anti-phishing training, and for Jobs' sake, patch all your vulns right away. The past year of intelligence collected by Cisco's Talos threat hunters suggests that attackers are moving faster to exploit vulns, and fooling more staff than ever into giving up their credentials. …

Categories: News

Google unleashes Gemini AI agents on the dark web

The Register - Mon, 23/03/2026 - 15:05
Claims it can analyze millions of daily events with 98 percent accuracy

Google's Gemini AI agents are crawling the dark web, sifting through upward of 10 million posts a day to find a handful of threats relevant to a particular organization.…

Categories: News

Smooth criminals talking their way into cloud environments, Google says

The Register - Mon, 23/03/2026 - 15:00
Voice phishing is second most common initial access method across all IR probes, and top in cloud break-ins

Voice phishing surged last year to become the second most common method used by cybercriminals to gain initial access to their victims' IT estate – and the No. 1 tactic used when breaking into cloud environments.…

Categories: News

US chip testing firm shrugged off ransomware hit as minor - then came the data leak

The Register - Mon, 23/03/2026 - 12:33
Trio-Tech International initially said hack wasn’t 'material,' but then stolen data was published

Trio-Tech International initially shrugged off a ransomware attack at a Singapore subsidiary as immaterial, only to reverse course days later after discovering stolen data had been disclosed.…

Categories: News

RSAC 2026: Uncle Sam backs out, and AI agents are everywhere

The Register - Mon, 23/03/2026 - 12:24
Infosec pros descend on San Francisco

kettle  When El Reg cybersecurity editor Jessica Lyons joins infosec industry colleagues in San Francisco for RSAC 2026 this week, she's expecting agentic AI to be on everyone's lips - at least those who aren't busy gossiping about the lack of presence from any representatives of the US federal government.…

Categories: News

Microsoft fixes broken Windows update days after vowing fewer broken updates

The Register - Mon, 23/03/2026 - 11:24
The era of reliability begins... right after this out-of-band patch

Microsoft has released an out-of-band update to resolve bugs introduced by a Windows patch just days after promising improved reliability.…

Categories: News

The drone swarm is coming, and NATO air defenses are too expensive to cope

The Register - Mon, 23/03/2026 - 10:14
Ukraine's battlefield lessons show quantity and affordability now trump exquisite hardware

NATO is unprepared to deal with attacks by cheap, mass-produced drones and urgently needs layered, affordable air defense systems to counter the threat, taking a cue from the experience gained by Ukrainian forces over the past four years.…

Categories: News

Russians are posing as Signal support to launch phishing attacks

The Register - Sun, 22/03/2026 - 22:12
PLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more!

Infosec In Brief  Russian intelligence-affiliated parties are posing as customer support services on commercial messaging applications such as Signal to compromise accounts and conduct phishing attacks, the FBI and Cybersecurity and Infrastructure Security Agency (CISA) warned last Friday.…

Categories: News

Cryptographers engage in war of words over RustSec bug reports and subsequent ban

The Register - Fri, 20/03/2026 - 21:07
Rust security maintainers contend Nadim Kobeissi's vulnerability claims are too much

Since February, cryptographer Nadim Kobeissi has been trying to get code fixes applied to Rust cryptography libraries to address what he says are critical bugs. For his efforts, he's been dismissed, ignored, and banned from Rust security channels.…

Categories: News

Pages

Subscribe to Sec Tec Limited aggregator - News