News
From pr0n to playlists and paperclips, trio of breaches spills data of millions
Three very different companies have now confirmed data breaches affecting millions of users – each insisting the damage stopped well short of passwords and payment details.…
MI6 chief: we'll be as fluent in Python as we are in Russian
MI6's new chief Blaise Metreweli outlined her vision for technology-augmented intelligence gathering in her first public speech on 15 December, warning that the UK operates "in a space between peace and war."…
PwC on using AI to turn cybersecurity risk into competitive advantage
Sponsored Post Managing cybersecurity risk has never been simple, but in today's threat landscape it can also become a source of strength. PwC believes that AI is now central to that transformation, helping organizations not just react faster to attacks, but evolve their defences with greater confidence.…
No, SoundCloud hasn’t started tuning out VPNs. It’s mopping up after a cyberattack
Music hosting and streaming service SoundCloud has admitted it suffered a cyberattack.…
Amazon security boss blames Russia's GRU for years-long energy-sector hacks
Russia's Main Intelligence Directorate (GRU) is behind a years-long campaign targeting energy, telecommunications, and tech providers, stealing credentials and compromising misconfigured devices hosted on AWS to give the Kremlin's snoops persistent access to sensitive networks, according to Amazon's security boss.…
China, Iran are having a field day with React2Shell, Google warns
At least five more Chinese spy crews, Iran-linked goons, and financially motivated criminals are now attacking React2Shell, a maximum-severity flaw in the widely used React JavaScript library, according to Google.…
Delay to European Central Bank messaging project cost the Bank of England £23M
The European Central Bank's (ECB) decision to delay its move to a new messaging standard in 2022 ended up costing the Bank of England £23 million as it was forced to adjust migration to a new settlement system to avoid compounding risks.…
JLR: Payroll data stolen in cybercrime that shook UK economy
Jaguar Land Rover (JLR) has reportedly told staff the cyber raid that crippled its operations in August didn't just bring production to a screeching halt – it also walked off with the personal payroll data of thousands of employees.…
Apple, Google forced to issue emergency 0-day patches
Apple and Google have both issued emergency patches after zero-day bugs were caught being actively exploited in what the companies describe as "sophisticated" real-world attacks.…
Denmark takes a Viking swing at VPN-enabled piracy
The Danish government wants the public to weigh in on its proposed laws restricting use of VPNs to access certain corners of the internet.…
Legal protection for ethical hacking under Computer Misuse Act is only the first step
Opinion It was 40 years ago that four young British hackers set about changing the law, although they didn't know it at the time. It was a cross-platform attack including a ZX Spectrum, a BBC Micro, and a Tatung Einstein slamming British Telecom's Prestel service over dial-up modems at 75 bits per second.…
Starlink claims Chinese launch came within 200 meters of broadband satellite
Asia In Brief A SpaceX executive has claimed that a Chinese satellite launch came within 200 meters of hitting a Starlink satellite.…
Honeypots can help defenders, or damn them if implemented badly
Infosec In Brief The UK's National Cyber Security Centre (NCSC) has found that cyber-deception tactics such as honeypots and decoy accounts designed to fool attackers can be useful if implemented very carefully.…
Microsoft RasMan DoS 0-day gets unofficial patch - and a working exploit
A Microsoft zero-day vulnerability that allows an unprivileged user to crash the Windows Remote Access Connection Manager (RasMan) service now has a free, unofficial patch - with no word as to when Redmond plans to release an official one - along with a working exploit circulating online.…
New React vulns leak secrets, invite DoS attacks
If you're running React Server Components, you just can't catch a break. In addition to already-reported flaws, newly discovered bugs allow attackers to hang vulnerable servers and potentially leak Server Function source code, so anyone using RSC or frameworks that support it should patch quickly.…
Microsoft promises more bug payouts, with or without a bounty program
Microsoft is overhauling its bug bounty program to reward exploit hunters for finding vulnerabilities across all its products and services, even those without established bounty schemes.…
Uncle Sam sues ex-Accenture manager over Army cloud security claims
The US is suing a former senior manager at Accenture for allegedly misleading the government about the security of an Army cloud platform.…
UK watchdog urged to probe GDPR failures in Home Office eVisa rollout
Civil society groups are urging the UK's data watchdog to investigate whether the Home Office's digital-only eVisa scheme is breaching GDPR, sounding the alarm about systemic data errors and design failures that are exposing sensitive personal information while leaving migrants unable to prove their lawful status.…
Half of exposed React servers remain unpatched amid active exploitation
Half of the internet-facing systems vulnerable to a fast-moving React remote code execution flaw remain unpatched, even as exploitation has exploded into more than a dozen active attack clusters ranging from bargain-basement cryptominers to state-linked intrusion tooling.…
Crypto-crasher Do Kwon jailed for 15 years over $40bn UST bust
Terraform Labs founder Do Kwon will spend 15 years in jail after pleading guilty to committing fraud.…