News

Claude collaboration tools left the door wide open to remote code execution

The Register - 7 hours 34 min ago
Anthropic fixed the flaws - but the AI-enabled attack surfaces remain

Security vulnerabilities in Claude Code could have allowed attackers to remotely execute code on users' machines and steal API keys by injecting malicious configurations into repositories, and then waiting for a developer to clone and open an untrustworthy project.…

Categories: News

Google catches Beijing spies using Sheets to spread espionage across 4 continents

The Register - Wed, 25/02/2026 - 20:41
UNC2814 historically targets governments and telcos

A China-linked crew found a unique formula for attacking telcos and government orgs across the Americas, Asia, and Africa in its latest round of intrusions. Google's threat intelligence, along with unnamed industry partners, disrupted the gang, which used the Chocolate Factory's own spreadsheet tools as part of its exploits.…

Categories: News

Fake 'interview' repos lure Next.js devs into running secret-stealing malware

The Register - Wed, 25/02/2026 - 16:51
Come for the coding test, stay for the C2 traffic

Next.js developers are once again in the crosshairs as hackers seed malicious repositories disguised as legitimate projects, according to Microsoft, which said a limited set of those repos were directly tied to observed compromises.…

Categories: News

Ex-L3Harris exec jailed 7 years for selling exploits to Russia

The Register - Wed, 25/02/2026 - 13:44
Former Trenchant manager profited millions from cyber tools reserved for the US

The former general manager of L3Harris's cyber arm will spend the next seven years behind bars for selling trade secrets to Russia.…

Categories: News

Wynn Resorts takes attacker's word for it that stolen staff data was deleted

The Register - Wed, 25/02/2026 - 12:39
Security pros question assurances as company offers staff credit monitoring

Wynn Resorts has confirmed that employee data was stolen from its servers, and is taking the hackers' word that they've since deleted it.…

Categories: News

OpenAI says Chinese cops used ChatGPT to plan and track smear ops against opponents

The Register - Wed, 25/02/2026 - 10:01
Note to secret agents: ChatGPT is NOT a private diary

A ChatGPT user with links to Chinese law enforcement tried to use the AI chatbot to run smear campaigns targeting the Japanese prime minister and other critics of the Chinese Communist Party, according to OpenAI's latest report on malicious uses of its models.…

Categories: News

Threat intelligence supply chain is full of weak links, researchers find

The Register - Wed, 25/02/2026 - 05:49
And they're being stressed by geopolitical concerns that threaten to slow important data-sharing efforts

Researchers from Georgia Tech have found that the supply chain for threat intelligence data is susceptible to adversarial action, and proposed a method to improve data sharing that they think will make it stronger.…

Categories: News

AI has gotten good at finding bugs, not so good at swatting them

The Register - Tue, 24/02/2026 - 22:36
Discovery is getting cheaper. Validation and patching aren’t

What good is finding a hole if you can't fix it? Anthropic last week talked up Claude Code's improved ability to find software vulnerabilities and propose patches. But security researchers say that's not enough.…

Categories: News

Patch these 4 critical, make-me-root SolarWinds bugs ASAP

The Register - Tue, 24/02/2026 - 19:55
SolarWinds + file transfer software = what attackers' dreams are made of

If you run SolarWinds’ Serv-U, you should patch promptly. Four critical vulnerabilities in the file transfer software can allow attackers to execute code as root.…

Categories: News

North Korea's Lazarus Group targets healthcare orgs with Medusa ransomware

The Register - Tue, 24/02/2026 - 18:25
New ransomware of choice, same critical targets

North Korea’s Lazarus Group appears to have added another tool to its kit. It has begun using Medusa ransomware in extortion attacks targeting at least one US healthcare organization and an unnamed victim in the Middle East, according to Symantec and Carbon Black threat hunters.…

Categories: News

Go library maintainer brands GitHub's Dependabot a 'noise machine'

The Register - Tue, 24/02/2026 - 16:31
When a one-line fix triggers thousands of PRs, something's off

A Go library maintainer has urged developers to turn off GitHub's Dependabot, arguing that false positives from the dependency-scanning tool "reduce security by causing alert fatigue."…

Categories: News

UK data watchdog fines Reddit £14.47M for letting kids slip past the gate

The Register - Tue, 24/02/2026 - 13:29
Social media giant retorts it doesn't want to collect 'private' data, and plans to appeal

The UK's data protection regulator has fined social media giant Reddit £14.47 million ($19.5 million) over its use of children's data.…

Categories: News

Korean cops charge teens over bike hire breach that exposed data on 4.62M riders

The Register - Tue, 24/02/2026 - 11:53
Public prosecutor mulls sentencing following investigations into two separate attacks

Two South Korean teenagers were this week charged with breaching Seoul's public bike service, Ttareungyi.…

Categories: News

UK tech hit by double trouble: Fewer foreign boffins amid skills squeeze

The Register - Tue, 24/02/2026 - 10:15
Visa applications down, executives emigrating, and AI blamed for the rest

The number of international workers applying for a visa to work in the UK's tech sector dropped 11 percent between Q2 and Q3 2025, and was down 6 percent year-on-year, according to consultancy RSM UK.…

Categories: News

Euro allies aiming to rapidly build low-cost air defense weapons

The Register - Tue, 24/02/2026 - 09:30
We like our surface-to-air weapons affordable

Britain has joined a handful of European allies in a program to develop low-cost air defense systems, including autonomous drones or missiles, with project delivery of the first elements scheduled for as early as 2027.…

Categories: News

Infosec community panics as Anthropic rolls out Claude code security checker

The Register - Mon, 23/02/2026 - 19:50
Not the first of its kind

ai-pocalypse  Anthropic sent the infosec community into a tizzy on Friday when it rolled out Claude Code Security, a new feature that scans codebases for vulnerabilities and suggests patches to fix the issues.…

Categories: News

Global regulators say AI image tools don't get a free pass on privacy rules

The Register - Mon, 23/02/2026 - 16:03
Watchdogs warn models that can generate realistic images of people must comply with data protection laws

A global coalition of privacy watchdogs has fired a warning shot at the generative AI industry, saying companies churning out realistic synthetic images can't pretend that data protection rules don't apply.…

Categories: News

Break free of Ring's servers, earn a five-figure bounty

The Register - Mon, 23/02/2026 - 15:17
Goal is to run software locally and stream only to owners' computers

If the sour taste has still not left your mouth after Ring's Super Bowl ad, there is a $10,000 prize for anyone who can find a security flaw in the company's cameras.…

Categories: News

Suspected Anonymous members detained in Spain over post-flood DDoS blitz

The Register - Mon, 23/02/2026 - 12:26
Quartet accused of attacking public institutions, claiming the government was responsible for 2024 tragedy

Spanish police say four self-proclaimed members of Anonymous are in custody after allegedly carrying out several cyberattacks on public authorities in the wake of the 2024 DANA floods.…

Categories: News

AWS says more than 600 FortiGate firewalls hit in AI-augmented campaign

The Register - Mon, 23/02/2026 - 11:41
Off-the-shelf tools helped Russian-speaking cybercrime group run riot

Cybercriminals armed with off-the-shelf generative AI tools compromised more than 600 internet-exposed FortiGate firewalls across 55 countries in just over a month, according to a new incident report from AWS.…

Categories: News

Pages

Subscribe to Sec Tec Limited aggregator - News