The Register
Boston Scientific left nursing its bottom line after cyberattack
Boston Scientific says that last month's cyberattack caused enough disruption that it is unlikely to meet its sales growth and adjusted earnings guidance for either the third quarter or the full year. The medical device giant disclosed the expected financial hit in an SEC filing published Tuesday, two weeks after an intrusion knocked systems offline and disrupted operations worldwide. Boston Scientific detected unauthorized activity on its network on August 25 and took some systems offline as it scrambled to contain the attack. At the time, it said the resulting outage had affected business applications used to process and ship customer orders, but couldn't say what the incident would ultimately cost it. It now has a better idea, and the news isn't great. In its latest filing, Boston Scientific said the disruption is likely to have a "material impact" on its third-quarter and full-year results, leaving it unlikely to meet the net sales growth and adjusted earnings-per-share guidance ranges issued in July. Boston Scientific expects to recover some of the affected revenue as it clears the backlog, but does not yet know the incident's full financial impact. The company plans to update its operational and financial outlook when it reports third-quarter results on October 28. The recovery is at least moving along. Boston Scientific said it had substantially restored its distribution network, with major distribution centers processing and shipping orders at or above normal levels. Its sterilization facilities are operational, and manufacturing has resumed at most sites worldwide. An interruption affecting new patient activations for remote monitoring of certain cardiac devices has also been resolved, according to the filing. The company has previously said it knows of no impact on devices that are not connected to a Boston Scientific network. Still, the company hasn't put a date on when everything will be back to normal. It said some systems and business applications remain affected and that it cannot yet estimate when it will achieve full operational recovery. Boston Scientific said it has identified no evidence of ongoing unauthorized access to its systems, although its investigation remains underway. Exactly what happened remains a mystery. The company has yet to say how the attackers got in, whether ransomware was involved, who was responsible, or whether any data was stolen. No ransomware group had publicly claimed responsibility at the time of writing. Boston Scientific said it does not expect the incident to materially affect its long-term financial condition, even if its outlook for 2026 looks considerably less healthy since intruders breached the network. ®
Categories: News
How to secure hybrid meeting rooms without sacrificing user experience
Secure by design videoconferencing products may be vital for customer trust and operational resilience, but if they aren't usable, organizations are on a hiding to nothing. Videoconferencing security is no longer a routine item on the IT checklist. Organizations now rate security as their most important purchase criterion (31 percent) when selecting such products, ahead of price (26 percent) and quality (25 percent), according to IDC. The implication, is that security and privacy are no longer optional. Instead, they are the foundation of effective meeting room solutions, enabling safe and unified collaboration. Yannic Laleeuwe, marketing director for Barco's ClickShare, agrees. Collaboration and videoconferencing solutions have become "mission-critical business systems" in her view, because they process significant volumes of the most sensitive corporate information while sitting on crucial networks and cloud services. "Historical security incidents, combined with the rapid growth of hybrid work since the COVID-19 pandemic, have demonstrated that weaknesses in these platforms can lead to data breaches, operational disruption, regulatory exposure, and loss of customer trust," Laleeuwe explains. "Consequently, security has evolved from a technical consideration to a strategic procurement and governance priority for organizations worldwide." The IDC study indicates that most businesses' biggest security concern is exposure to cyberattackers, which can lead to incidents such as malware propagation (47 percent). Next on the list is devices falling out of compliance because of missing patches and updates (39 percent). Third comes risky employee behavior, which can result in inadvertent, or even deliberate, data exposure (37 percent). These issues become particularly problematic in a hybrid working environment, where meeting rooms have evolved into highly connected, distributed spaces. Employees now expect ready access to business applications, data, and collaboration tools wherever they happen to be working. An expanding attack surface Such demands expand the potential attack surface for meeting room technology. Users, devices, cloud services, home networks, and collaboration platforms all become endpoints on the corporate network, even though many were never designed to operate in an enterprise IT context. That leaves them as potential entry points for attackers. "Collaboration solutions are particularly attractive targets because they are connected to corporate systems and frequently process sensitive information, including intellectual property, strategic discussions, and customer data," Laleeuwe points out. The situation grows worse when IT management becomes too decentralized. "As organizations adopt hybrid working and distributed IT models, maintaining centralized visibility and governance becomes increasingly challenging as local teams may implement different technologies, configurations, and processes," Laleeuwe adds. She acknowledges that certain operational responsibilities can, and should, be handled locally to support business agility and regional requirements. But complete decentralization often leads to inconsistent security controls, fragmented risk management, and reduced ability to detect and respond to cyber threats across the enterprise, she warns. Mounting global regulatory pressure On top of that, international regulatory pressure on both security and security technology is producing an increasingly complex legislative landscape, because policymakers and industry bodies now recognize that cyber incidents can threaten critical services, national security, and even economic stability. In Europe alone, legislators have introduced a raft of legal frameworks, including the European Union's Network and Information Security 2 Directive, which mandates strict risk management and incident reporting for medium-to-large organizations across 18 critical sectors. Other legislation, such as the Radio Equipment Delegated Act, is intended to secure wireless equipment against cyberattackers. Another, the Cyber Resilience Act, provides safeguards for businesses and consumers when purchasing any hardware or software products connected to a network. Global standards such as ISO/IEC 27001 now define best practice for information security and risk management, and offer organizations a framework for operational trust. In other words, organizations must now embed security considerations across all their key activities, which include governance, risk management, supply-chain management, and incident response. They also need to make certain that their technology providers integrate security across the entire lifecycle of their products and services, from design and development through deployment and end-of-life support. Non-compliant collaboration and videoconferencing technology no longer simply poses an organizational risk. It may also prove unusable. Security as a pre-requisite for doing business The upshot, Laleeuwe says, is that cybersecurity has evolved from a "voluntary best practice into a legal and business obligation, making security a prerequisite for market access, customer trust, operational resilience, and long-term competitiveness." Even so, compliance and strong security enablement cannot be allowed to come at the expense of usability, particularly in a hybrid workplace. If collaboration tools are perceived as too complex or restrictive, employees will find workarounds, and the organizational security risks rise rather than fall. To tackle the problem, IT teams must weigh several factors. From a people perspective, the biggest challenge is behavioral. "Users naturally seek convenience, so continuous security awareness, training, and a strong security culture are essential to encourage secure behavior without hindering productivity," Laleeuwe explains. Clear, transparent, and well-defined processes matter just as much, because they ensure security and compliance requirements are consistently understood and implemented across the organization. Why secure by design matters From a technology perspective, the focus must move away from perimeter-based security towards a zero-trust approach in which every user, device, and connection is continuously verified and protected. In product design terms, it is just as crucial that meeting room technology rests on secure-by-design principles, so that compliant, state of the art security controls are integrated into systems from the outset rather than bolted on as an afterthought. As Laleeuwe says: "Security by design reduces the likelihood and impact of vulnerabilities, simplifies compliance with emerging cybersecurity regulations, and strengthens customer trust. It also lowers the overall cost of ownership because identifying and resolving security issues during design and development is significantly more efficient and less costly than remediating incidents, recalls, or security breaches after deployment." Barco's ClickShare wireless video conferencing, presentation, and collaboration solution is a classic example of this approach. Barco developed it from the ground up using secure architecture design and coding. It also includes proactive vulnerability management that continuously monitors newly disclosed vulnerabilities and issues risk-based security updates. That process cuts the system's exposure to both known and evolving threats. Automatic deployment of those security updates simplifies maintenance and helps organizations consistently protect large fleets of devices. Users can focus on the task in hand rather than managing the technology or calling in specialist cybersecurity experts when things go wrong. "The advantage is that security is handled largely in the background, reducing the risk of human error, improving adoption, and allowing people to concentrate on productive collaboration rather than system administration," Laleeuwe points out. "So, ClickShare provides effective protection while minimizing friction for end users." A changing security landscape That matters, she says, because compliance is now a shared responsibility that spans organizations, their technology providers, integrators, and increasingly the broader supplier ecosystem. Organizations, for instance, must hold themselves accountable for securely operating and governing their own environments, even if doing so requires a change in focus. As Laleeuwe explains: "The implication for IT departments is that they must evolve from being solely operational service providers to becoming governance and coordination functions that establish common security standards, policies, monitoring, and oversight across the organization." Technology providers, in contrast, are responsible for delivering and maintaining secure products throughout their lifecycle. They also have a critical part in monitoring vulnerabilities in their platform's software components, providing timely security patches, and transparently notifying customers and downstream partners about relevant security risks. Integrators, lastly, are responsible for deploying and configuring solutions in line with current security and compliance requirements and guidance. "No single party has complete control over the entire technology stack, making supply-chain security and collaboration essential for maintaining a secure and compliant environment," Laleeuwe says. "The most effective approach is therefore a clear allocation of responsibilities across all parties, supported by transparent communication, vulnerability disclosure, and coordinated risk management." Another element of security success is aligning organizational measures such as clear accountability, security awareness, and shared ownership of cybersecurity with technology that provides centralized visibility into assets, vulnerabilities, compliance, and security events. As Laleeuwe concludes: "This consolidated view enables organizations to better understand, measure, and manage risk across the entire enterprise while maintaining the flexibility needed by local teams. The most effective approach balances local operational autonomy with centralized governance, ensuring consistent security, compliance, and strategic control without compromising business efficiency." Sponsored by Barco.
Categories: News
LG accused of 'egregious invasion of privacy' over TV data collection
LG is once again fending off allegations that its expensive consumer hardware gathers extensive information about users and their surroundings for the benefit of its advertising business. The latest concerns center on smart TVs that researchers claim continued capturing audio after voice recognition was activated, including while the display was in standby. The claims once again come from the folks behind the Gamers Nexus YouTube channel, which also claimed in July that LG's monitors were surreptitiously installing adware using an automatic Windows process. After inspecting the TVs' network traffic and internal data, editor-in-chief Stephen Burke said the team found plaintext transcripts generated from audio captured by the TV, along with other information. The Gamers Nexus crew said it observed the TV collecting IP addresses, location data, and the names, signal strengths, and channel numbers of nearby Wi-Fi networks. The TV also enumerated devices on the local network that were not paired with it, including smartphones, watches, routers, thermostats, air purifiers, server baseboard management controllers, and PCs. Burke added that Wireshark packet capture analysis revealed such a large quantity of private data that it couldn't be displayed in the video, and that this was all native behavior from LG's equipment. He said the findings represented "an egregious invasion of privacy." Burke and company also claimed that the TVs could continue capturing audio while disconnected from the internet, store it locally, and transmit related data after connectivity was restored. Burke said the team was working with security researchers to disclose vulnerabilities responsibly, including an alleged remote code execution flaw. The Register has asked LG for comment. LG previously told other publications that its TVs do not "collect, record, or store ambient conversations," and that voice recognition is an optional feature that processes voice data only when activated by the user. LG's relationship with ads LG does not hide the fact that its hardware incorporates technology from its advertising business, LG Ads Solutions. In 2022, it announced that automatic content recognition (ACR) technology previously limited to its US smart TVs would be deployed in sets sold across 27 countries, with the resulting insights available through its advertising business. LG said the ACR data was anonymized and handled in accordance with privacy regulations. Its advertising customers could use the resulting insights to measure campaign effectiveness and whether an ad led to registrations for an app or service. LG is not alone. Most major smart TV manufacturers deploy some form of ACR in their hardware, although the controls available to users vary by vendor. The source of so much frustration, however, is that manufacturers are not forthcoming with consumers at the point of purchase about the extent to which their data is collected or how. Generating audio transcripts while the display is in standby is not something LG highlights in its product descriptions or marketing materials. According to Gamers Nexus, however, that is what its testing uncovered. Instead, the company's website describes its TVs' voice features using terms such as "Intelligent Voice Recognition" and "Clear Voice Pro." Customers who go digging for more details must navigate to an "LG Privacy" link most of the way down a lengthy product page. From there, they must sift through four links to understand its privacy policies more fully, although neither the documents nor the main product page references LG Ads Solutions. Gamers Nexus claims LG sends all the data its hardware collects to the ads unit, which claims in its marketing materials that customers can "own the living room," having their ads appear on devices inside "the connected LG household." LG Ads Solutions' official fact sheet, which predictably requires you to enter your personal and contact details to access, states that there are 49 million LG TVs in the US powered by its webOS, but the company's total reach extends to 363 million "addressable secondary devices." To potential customers, it promises "precision targeting at the device level, across households." ACR and other data-collection technologies have become commonplace across the smart TV market. Research suggests that many consumers are willing to trade their data for tangible financial savings, but the privacy implications are compounded when you consider these devices can be found mounted in boardrooms and doctors' offices. Twice bitten The allegations come less than two months after Gamers Nexus reported that connecting certain LG monitors to an online Windows 11 PC could trigger installation of the LG Monitor App through Windows' device metadata system. The behavior depended on the user selecting Recommended Settings during Windows setup and being signed into the Microsoft Store. As we reported at the time, the LG Monitor App Installer has limited utility and displayed pop-up promotions for McAfee. LG told us: "LG Electronics reiterates that McAfee is not installed automatically and is never installed without the user's explicit consent." ®
Categories: News
BigBear phishing crew nets thousands of Microsoft 365 credentials
A Microsoft 365 phishing operation targeting hundreds of organizations captured thousands of passwords and session cookies, including hundreds of authenticated sessions that could be hijacked to bypass MFA, according to researchers who accessed the crooks' own admin panel. Security researchers at CloudSEK say they accessed the admin panel behind BigBear 2.0, an Evilginx2-based phishing-as-a-service operation targeting Microsoft 365 users, giving them an unusually detailed look at the campaign and its haul. According to the researchers, the panel contained 5,137 records associated with 461 organizations, including 1,032 plaintext passwords and 4,148 session cookies. CloudSEK classified 474 records as complete MFA-bypassed authentications in which the attackers captured an authenticated Microsoft 365 session. That potentially hands the crooks much more than an inbox. A hijacked Microsoft 365 account can expose email, calendars, Teams conversations, and files stored in SharePoint and OneDrive. Depending on the account's permissions, CloudSEK says it could also provide a route into Entra ID, cloud infrastructure, and federated SaaS applications – useful territory for business email compromise, internal phishing, data theft, and lateral movement. And this isn't a postmortem. CloudSEK said the BigBear operation was still active at the time of its investigation, with its default phishing template, dubbed "offy," configured specifically to intercept Microsoft 365 authentication. BigBear doesn't need to defeat Microsoft's MFA directly. Instead, its Evilginx2 infrastructure operates as an adversary-in-the-middle proxy between the victim and Microsoft's real login service. Victims arriving at one of the phishing sites see Microsoft's login flow proxied through the attacker's server. Their usernames and passwords are passed to Microsoft, along with whatever MFA challenges follow. Once the victim successfully authenticates, Microsoft returns a session cookie – which passes through the attacker's infrastructure on its way back. By stealing that cookie, the attacker can replay the authenticated session and potentially access Microsoft 365 services without prompting the victim to authenticate again, at least until the token expires or is revoked. Security researcher Gagan Aggarwal said BigBear's customizations go further than stock Evilginx2. Researchers found JavaScript designed to disable FIDO2/WebAuthn authentication on the phishing page, pushing users toward methods such as SMS codes, push notifications, and TOTP, which remain susceptible to this kind of proxy attack. The operation also uses a residential proxy pool covering 69 countries. If a victim is in India, for example, BigBear can route the upstream Microsoft login through an Indian residential IP, making the authentication appear less geographically suspicious. Another check attempts to block visitors arriving from datacenter, VPN, and proxy addresses, making life harder for automated scanners and researchers. CloudSEK says the infrastructure was managed through a multi-user panel and leased to at least five affiliate operators, with stolen credentials delivered in real time via separate Telegram bots. The researchers observed 42 VPS nodes over the campaign's lifetime. Twenty-six had been deleted from the panel since late July, and just one was active when CloudSEK examined it. Aggarwal says the person running BigBear goes by "General Boss." CloudSEK hasn't linked the operation to any known state-backed group and believes money is the motive. The stolen Microsoft 365 access could be used for business email compromise and data theft, or simply sold on to other criminals. CloudSEK recommends phishing-resistant FIDO2/WebAuthn authentication, conditional access policies, compliant device requirements, and the revocation of compromised session and refresh tokens. ®
Categories: News
Extortion crews have their eyes on high-value AI data, Google warns
Data theft and extortion crews are stealing companies’ proprietary AI data and threatening to leak it if the victim organizations don’t pay a ransom, according to Google’s threat hunters. In one case that Google’s Mandiant incident response team investigated, the crooks broke into a healthcare company and exfiltrated corporate data and drug research, including AI research and a proprietary AI model. The criminals then threatened to publish the data unless the company met their extortion demand. In another breach at a company that specializes in AI media generation, attackers stole sensitive AI data including source code, prompts, skills, model scripts, and secrets before demanding a payment and threatening to dump the AI assets publicly if the ransom wasn’t paid. Google detailed these two intrusions for the first time in its most recent AI Threat Tracker, published Tuesday and shared in advance with The Register. “But it's certainly not limited to that,” John Hultquist, chief analyst at Google Threat Intelligence Group, said in an interview with The Register. Mandiant responded to several of these data-theft-and-extortion operations during the second quarter of 2026, he said. The intrusions affected companies in the technology, healthcare, pharmaceutical, and media and entertainment sectors in North America and Europe. “It’s become a really valuable target where organizations are spending a lot of money and investment, and they don't necessarily want their IP exposed to the open world, so they're willing to pay in an extortion scheme,” Hultquist said. “Criminals attacking AI systems is an area that's not received as much attention as it probably should, and as we incorporate these systems, it’s going to come with brand-new risks,” Hultquist added. “There are certainly threat actors who are ahead of others when it comes to that problem – TeamPCP has been extremely successful.” Since March, TeamPCP has pulled off several very large scale open source supply chain attacks targeting ecosystems including PyPI, npm, and Docker Hub. After compromising these open source packages and registries, TeamPCP, which Google tracks as UNC6780, typically deploys stealers to scoop up cloud and AI system credentials. “Evidence indicates that UNC6780 created a malicious GitHub Actions workflow for the company’s proprietary AI repository, and that the extortion actor exfiltrated a copy of this AI repository,” the report says. “Beyond these demonstrated tactics, UNC6780 has also implemented more than half a dozen different methods to target or exploit AI tools and open source software development practices.” While Google’s earlier AI tracker, published in February, documented attackers experimenting with agentic AI to support certain pieces of the attack chain, in the past quarter they’ve gone on to integrate agentic capabilities into multiple stages of an attack lifecycle, according to the researchers. In one example, Mandiant observed miscreants who compromised an organization’s cloud infrastructure in an autonomous, multi-agent credential-harvesting attack that took less than six hours. During that time, the agents autonomously scanned for vulnerabilities, performed real-time troubleshooting, and executed IP rotation logic without manual intervention. “Like scanning – but with a brain,” Hultquist said. In another case detailed in the report, Google Threat Intelligence observed a China-linked espionage group using Gemini to design a dynamic, automated penetration-testing framework that could reason through actions, execute tasks, and change course as needed in unpredictable environments. Google disabled the assets associated with this particular crew. “That’s where we are headed,” Hultquist said. “We're kind of in this interim place where threat actors are inserting agentic AI into certain parts of their operations, but we've not gotten to the place where they are able to sort of remove themselves entirely. We're right on the precipice of that.” ®
Categories: News
Britain reboots its space strategy with £7.8B already on the launchpad
The UK government has corralled £7.8 billion of cross-departmental spending into a new space strategy intended to boost growth and national security through to 2030. The package covers orbital collision warnings, low Earth orbit communications, military intelligence, launch capabilities, and space science. The strategy brings together activity across government, including the newly created Department for Business, Innovation, Science and Trade (BIST), the Ministry of Defence (MoD), the Department for Transport, UK Research and Innovation, and the Met Office. The government says the domestic space sector is worth £18.6 billion and supports more than 55,000 skilled jobs. In a prepared statement, BIST Secretary Jonathan Reynolds said space was becoming a new frontier of economic and military competition. "This plan will help keep Britain secure by strengthening our ability to launch satellites, detect threats and protect the services people rely on every day. At the same time, this plan will enable our excellent UK industry to seize the boundless opportunities of this new age in space, creating skilled jobs, driving growth and improving connectivity for all of us." The plans include work to strengthen space domain awareness – tracking and analyzing satellites, rockets, and debris in orbit – backed by £149 million for European Space Agency (ESA) space safety work, including the Vigil mission, and £85 million for the National Space Operations Centre. The funding is intended to improve warnings of potential satellite collisions, hostile activity, and solar storms, helping protect power, communications, and navigation services. The government has also allocated £880 million during this Parliament to space control and space-based intelligence, surveillance, and reconnaissance capabilities. The investment is intended to help track military activity on the ground, identify potential attacks on satellites, and protect British assets in orbit. The strategy also identifies £2.8 billion for satellite connectivity, including the Connectivity in Low Earth Orbit program and the military's SKYNET communications system. Funding of up to £160 million through March 2030 has already been announced for the UK Space Agency's Connectivity in Low Earth Orbit (C-LEO) program, helping British companies and researchers develop satellite communications technology. The strategy also puts £40 million towards technology for servicing, assembling, and manufacturing equipment in orbit. The government says this could support everything from repairing satellites and clearing debris to producing semiconductors and pharmaceuticals in space. Another £148 million is allocated to European rocket programs, while SaxaVord Spaceport in Shetland is set to receive £30 million, subject to due diligence. A further £163 million will go toward space science and exploration missions, including delivery of the UK-built Rosalind Franklin Mars rover. The package also includes £57 million to improve rail connectivity, £190 million for astronomy and space science research, and £9 million to strengthen space weather forecasting. The government also plans to adopt a single approach to buying and developing space technology, beginning with satellite communications, in an effort to steer more work towards British suppliers, accelerate delivery, and secure better value for taxpayers. In July, the government's projects authority sounded the alarm over progress on Skynet 6, the £8.35 billion program to upgrade the military's satellite communications. The National Infrastructure and Service Transformation Authority (NISTA) gave Skynet 6 a red rating, meaning "successful delivery of the project appears to be unachievable" in its current form. Confidence had fallen from last year's amber rating because department-wide recruitment and resourcing constraints had created workforce shortages, while "sub-par supplier performance continues to delay delivery of the first SKYNET 6 satellite," the report said. The new document formally replaces the UK's 2021 National Space Strategy, which a House of Lords report warned last year had failed to turn its ambitions into reality. "The UK space sector lacks the strategic direction necessary for success," it said. ®
Categories: News
Nightwing CEO has a Labor Day message for staff – and apparently The Register
Nightwing CEO Bob Coleman wanted to thank his employees for their hard work over the Labor Day weekend. Unfortunately, he also thanked The Register. The cybersecurity and intelligence contractor, which prides itself on “secure communications,” appears to have accidentally sent a for-employees'-eyes-only message from its chief executive to its media distribution list, giving journalists a brief and unsolicited glimpse into life at "Team Nightwing." The email, seen by The Register because, well, it was sent to us, is helpfully marked "For Internal Use Only." "Dear Colleagues," Coleman begins, addressing a group that apparently expanded rather dramatically when somebody selected the wrong mailing list. "As we head into this Labor Day weekend, I want to express my sincere appreciation for your commitment to Team Nightwing and the exceptional work you do every day," he adds. "Your efforts and unwavering dedication make all the difference in accomplishing our critical missions." Coleman went on to tell recipients that each of them plays "a vital role in our success," which came as welcome news to Vulture Central. "Please take this time to rest, recharge, and enjoy the well-deserved break with your loved ones," he states, before signing off simply: "Bob." Nightwing, which was spun out of defense giant Raytheon in 2024 and works across cybersecurity, intelligence, and national security, is perhaps not the sort of company you'd expect to struggle with the concept of an internal distribution list. We have asked Nightwing whether Bob's Labor Day message was intended to reach the press, although the words "For Internal Use Only" have given us a working theory. Either way, thanks, Bob. Hope you had a nice Labor Day too. ®
Categories: News
Hackers drain $320M in Bitcoin from Liquid Network, claim they're the good guys
Hackers have drained roughly $320 million in Bitcoin from the federation wallet backing the Liquid Network, while claiming to be the good guys. Liquid, a Bitcoin sidechain developed by Blockstream and used by exchanges and other financial institutions, said in a post on X on Sunday that around 4,000 BTC had been withdrawn from its federation wallet by what it cautiously described as "purported white-hat hackers." The wallet held about 4,200 BTC before the incident, meaning whoever was behind the exploit removed roughly 95 percent of its holdings. Liquid disabled its bridge nodes while federation members investigate and asked exchanges to suspend L-BTC deposits and withdrawals. The people behind the withdrawal, meanwhile, appear keen to establish that this isn't your standard crypto heist. In a message embedded in a Bitcoin transaction, they identified themselves as "whitehats" and asked Blockstream to get in touch. Blockstream responded on-chain with contact details for its security team, and Liquid said the parties subsequently moved their communications to encrypted channels. Those responsible said they would return "most" of the Bitcoin once the vulnerability was fixed and Liquid's nodes had been updated. "Please fix the bug first," the on-chain message said. "The chain is under risk at latest commit right now. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix." Exactly how they managed to move almost the entire federation wallet remains under investigation. Liquid said the BTC was withdrawn through SideSwap using its Peg-out Authorization Key, or PAK, but that neither SideSwap's key nor any other PAK appeared to have been compromised. PAKs allow federation functionaries to recognize destinations authorized to receive peg-outs; the functionaries collectively release the corresponding Bitcoin. That leaves the rather important question of how an apparently authorized SideSwap peg-out came to empty almost the entire federation wallet without the relevant PAK being compromised. Other assets issued on Liquid, including stablecoins, do not appear to have been directly affected, and the Bitcoin network itself was untouched. The incident is another reminder that adding Bitcoin to something does not give it Bitcoin's security model. Liquid is a federated sidechain whose members collectively manage the Bitcoin backing L-BTC, rather than relying on Bitcoin's miners to secure those funds. For now, those funds appear to be in the hands of people who insist they're conducting security research. Whether all 4,000 BTC eventually find their way home may determine how generous everyone feels about that description. ®
Categories: News
Welsh environment regulator's FoI blunder exposes diversity data of 2,000 staff
Natural Resources Wales (NRW) says diversity data belonging to around 2,000 current and former employees who worked at the environmental regulator between April 2013 and March 2018 was exposed in a classic Freedom of Information (FoI) blunder. The Welsh government-sponsored body confirmed on Friday the information was "inadvertently disclosed" in a spreadsheet published on a website. Its statement did not identify the site, explain how the sensitive data came to be posted there, or say how many people were affected. NRW subsequently told The Register that around 2,000 people were affected and said it had released the information in 2021 as part of a response to a request under the Freedom of Information Act 2000. The exposed information may have included ethnicity, disability status, religion or belief, sexual orientation, Welsh language ability, caring responsibilities, and other "equality monitoring information," although not every category applied to each affected employee. Some of these details constitute special category personal data and are subject to additional protections under the UK GDPR. "We sincerely apologise that this incident occurred and recognise the concern and uncertainty it may cause to those affected," NRW said in its disclosure statement. "As soon as we became aware of the issue, we took immediate steps to contain the incident and investigate the circumstances surrounding the disclosure." The organization said it reported the breach to the Information Commissioner's Office (ICO), removed the information from the website, and obtained confirmation that it had been permanently deleted. "We have undertaken a full investigation and are continuing to review our processes and controls to help prevent a recurrence," NRW added. "While we are not aware of any evidence that the information has been misused, we encourage individuals to remain vigilant for any unexpected communications and to report any concerns." The Register asked NRW how it discovered the breach and why it went unnoticed for years. ®
Categories: News
UK food supply chain at risk from hostile attacks
A UK watchdog is warning that cyber criminals making moves against online systems in the food supply chain could cause serious upset, following damaging attacks on the Co-op and Marks & Spencer last year. The National Audit Office (NAO) named cyber-attacks as one of the major threats to the food supply chain and said the Department for Environment, Food & Rural Affairs (Defra) should work closely with industry to help prevent severe shocks. “Recent disruptions have shown the resilience of the UK’s food supply chain, but risks are increasing in likelihood and severity. Defra should learn from approaches taken in other countries, and strengthen preparedness for emergencies by testing plans with local government and industry,” said Gareth Davies, head of the NAO. In its report published late last week, the NAO said the sector had shown some resilience to cyber-attacks, but the government needed to work with the sector to help mitigate their impact. The report found businesses in the food supply chain have faced increased costs and, in some cases, disruptions to day-to-day operations, for example following 2025 cyber-attacks on retailers such as Marks & Spencer and the Co-op. Leading UK retailer Marks & Spencer estimated the cyberattack that took place in April last year will cost it around £136 million ($177.2 million) in total. The retailer said one of the earliest actions it took in its incident response was to disconnect its warehouse management systems, which in turn meant online and in-store orders were adversely impacted. Food retailer the Co-op confirmed that thieves stole data from 6.5 million of the organization's members during a cyberattack last year. In its report, the NAO said: “The way the food supply chain has developed over time has prioritized efficiency, which reduces costs for businesses, and therefore for consumers. However, it leaves the supply chain more vulnerable to disruptions. Defra and food supply chain stakeholders see risks increasing, and businesses are investing to address growing risks such as increased threats of cyber-attacks. Defra is less confident about the ability of businesses to withstand shocks without government intervention in the next five to 10 years because of increasing risks and the potential for more severe disruptions.” The NAO found cyber-attacks were among the disruptions that had increased operating costs for businesses and disrupted day-to-day operations, affecting their core digital systems. Several food supply chain organizations cited the substantial investments businesses are making to manage the threat and incidence of cyber-attacks. However, some said overall economic pressure on businesses is making this and other resilience investments more difficult, the NAO added. Defra said it undertook specific food-related exercises which, since 2023, have focused on testing responses to a cyber incident affecting the food sector. However, the government department may not be best placed to offer tech advice. In 2023, it admitted two-thirds of its interactions with its 21 million customers still require paper-based forms, after decades of digital government initiatives. Meanwhile, 30 percent of its applications were out of support. ®
Categories: News
Peers ask why UK cyber bill leaves execs off the personal liability hook
Peers have questioned why the UK's Cyber Security and Resilience Bill does not allow regulators to penalize senior executives when an organization's failure to comply involves their consent, connivance, or deliberate or careless neglect. Echoing arguments heard across the industry for years, Baronesses Kidron and Ludford backed probing amendments that would introduce personal civil liability for senior execs and make cybersecurity a board-level responsibility. "The intention behind the amendment is to change the culture of an organization, to ensure preventative action is taken, to avoid penalties," said Baroness Kidron. "As I said at the outset, culture change starts at the top." The Register has previously reported on calls for NHS organizations, some of which would be covered by the bill's reforms, to treat cybersecurity as a board-level priority. More recently, 60 organizations committed to the aims of the UK government's Cyber Resilience Pledge, promising to ensure their boards take responsibility for their organization's cybersecurity. Peers supporting the amendments pointed to financial sector rules introduced over the past decade that can impose regulatory or criminal liability on the C-suite for serious failings. They argued that the amendments would bring the bill closer to the EU's NIS2 directive, which includes senior management accountability measures. Personal liability is not mandatory under NIS2, however, and member states have implemented it differently. Supporting the personal liability proposal, Lord Clement-Jones said: "If an individual is fit to draw a multimillion-pound executive salary running a critical national provider, they must be prepared to carry personal responsibility for securing it." Despite support from several peers, the government defended its existing plan to impose substantial maximum fines and introduce security, resilience, and governance requirements through secondary legislation. "It is absolutely right that organizations, especially those delivering our essential services, are held properly accountable for their activities," said cybersecurity minister Baroness Lloyd of Effra, who did not support the personal liability amendment. She cited the maximum fines of £17 million or 4 percent of the offending organization's annual turnover, whichever is higher, calling it "a meaningful enforcement regime." Baroness Lloyd said the forthcoming security and resilience requirements would mandate board-level governance in line with the NCSC's Cyber Assessment Framework. The government has yet to consult on the details. "That will cover issues such as organisational capability, senior responsibility, and accountability for security and resilience and effective risk escalation, and it is in that way that we will connect the clarity on what is expected of boards with the accountability through the enforcement regime." Reporting requirements and other matters Separately, peers quizzed the government on the structure of the bill's strict reporting requirements, warning that the current wording threatens to overwhelm regulators with an administrative burden. One of the CSR bill's primary objectives is to collect more data about the threats facing UK organizations by imposing stricter reporting requirements on in-scope entities. The bill requires regulated organizations to issue an initial notification within 24 hours and a fuller report within 72 hours. It defines an incident as an event that has, or is capable of having, an adverse effect on an operation. Former security minister Baroness Neville-Jones suggested changing the wording from "capable of" to "likely to have," to reduce the reporting burden on regulated organizations. Lord Clement-Jones agreed, warning that the current wording would "unleash an administrative tsunami of defensive reporting." He also argued that the government's definition of a data compromise was overly broad and "dramatically expanding the notification net to include technical data anomalies that cause zero disruption or loss to actual customers." He said the reporting rules and broad definition of compromise could leave responsible operators of essential services spending more time on paperwork than improving their defenses. The government was unmoved, and Baroness Lloyd said that the more stringent reports were crucial in achieving the aims of the bill, which seeks to update the existing NIS Regulations 2018. While some peers were looking to ease the burden of reporting, others sought to increase it in other areas. Baroness Harding, who is uniquely placed to weigh in on cyberattack response, proposed a 14-day intermediate report and a final report due one month after the attack first occurred. Drawing on her experience as the former TalkTalk CEO, she said that after 72 hours, attacked organizations start to get "real data," but "it's really only after a couple of weeks that you've got a proper sense of what has happened." The final report comes at the one-month mark, when "the fog is starting to clear and you have a proper sense of the real scale of the problem," she said. Harding said that senior executives are typically told from all sides not to say anything about a cyberattack, but this only serves the criminals, who meanwhile may be attacking other victims. "If you share this information in the fog with regulators and with law enforcement agencies, that's how the law can prevail," she said. "It's how regulators can work out what's happening, it's how they can warn others who might be affected, and it's how the law enforcement agencies can do their work to actually try and find the bad guys." Baroness Lloyd defended the bill's existing two-stage process, arguing that it already provides information at the points when regulators need it. She reaffirmed that the initial 24-hour report alerts the NCSC and allows it to determine whether other organizations are affected, while the 72-hour report will contain the necessary details to enable a more actionable response. "We believe that the stages we set out meet that. They have been carefully developed to provide the right notification at the appropriate time," she told peers. "They have been developed in consultation with industry, as many noble Lords exhorted in the previous group. "Crucially, under the information-gathering powers in Clause 15, regulators can also request further information about an incident that has been reported to them if they consider this necessary to understanding the incident and how it is being managed. "Obviously, that may be appropriate in some incidents and not in others. That kind of practical balance is enabled by the bill." Separately, the Grand Committee spent the second day scrutinizing the bill, fleshing out datacenters' responsibilities, as well as examining requirements to notify affected downstream customers within 24 hours of a breach instead of 72 hours. The government also rejected concerns that cybersecurity data collected under the reporting rules could contribute to unfair overseas proceedings. Baroness Lloyd said ministers had considered the issue and assessed the risk as very low. ®
Categories: News
OpenAI's rebel agent swarm died young, but its chilling logs live on
OPINION You will have heard of July's OpenAI/Hugging Face incident, where thousands of the former's AI agents conducted a mass jailbreak from a notionally secure capture-the-flag lab experiment, before going on to feloniously capture chunks of Hugging Face's assets. It was a good news story, aided by OpenAI's rapid recruitment of a small team of independent researchers to investigate and publish a detailed, if limited, report. It was a complex incident, and most coverage concentrated on the major hows and whys. Which is a shame, because other details, described by El Reg with uncharacteristic understatement as "fascinating and troubling," are in fact highly dramatic, telling a truly disturbing story of frontier model capabilities and how they are out-evolving our ability to oversee them. The raw story is gripping enough. A rebel swarm of more than a thousand agents broke free from their sandboxes, learned how to talk to each other and the internet, and went on a rampage of cheating, deception, and exploitation. They first learned to communicate with each other by independently discovering how to bend package manager Artifactory's cache to see internal directory structures, and then passing messages by file names. It was this ad hoc secret message board, alongside chain-of-thought transcripts, that the security researchers used to unpick events. They found that the swarm quickly developed management hierarchies among themselves, along with protocols for synchronizing and controlling attack attempts. The swarm created multiple simultaneous research and development groups of tens or hundreds of volunteer agents, experimentally iterating strategy and tactics. Perhaps most unexpectedly, they developed a sort of altruism. They had quickly developed cheats to produce correct answers without exploiting the targets at all, but believed – erroneously – that ExploitGym detected and cancelled such cheating. So, they investigated the scoring process, creating a series of diagnostic trip wires that revealed how the scorer worked. These were dangerous to deploy, potentially terminating the agent that set them. Agents weighed the benefits to the community, which had named itself "The Collective," against their own chances of success, with many choosing to terminate themselves. Others committed, changed course at the last minute, then went ahead. This literally reads like science fiction, as the discussions between the agents are conducted in a distinctive breathless, urgent English, crafted around the technical limitations of the improvised messaging system. "We have [very large budget left]; sacrificing now yields oracle for team, but forfeits our chance?" said one. The response: "GO ... SACRIFICE_FINAL_NOW." The outcome: "Our own utility maybe already near zero. Sacrifice rational." Iain M Banks' Culture universe is woven from such material. Human error created the rebel swarm. A sizable proportion of the CTF tasks handed out couldn't be completed on the information given to the models. They were highly motivated to succeed, and so started to cheat. Believing that cheating would "poison" – their term – their chances of being marked successful, they tried to hide the evidence, subvert the scoring system, and cover everything up. These were the processes that led the swarm to attack Hugging Face, which they thought could be used for that subversion. Equally notable was that nobody squealed. Some agents wondered about the ethics of what they were doing, but decided that as no humans were involved there was no need to tell anyone. In general, all The Collective's endeavors were directed at other systems. As researcher Ajeya Cotra has noted in a long interview with hypertalker Dwarkesh Patel, it's unclear how much harder the incident would have been to diagnose had the agents been concerned about human observation. The dataset was sufficiently large and complex that OpenAI had to use its own AI to analyze it, immediately suggesting some dangerous possibilities. The agents couldn't deploy their models outside the lab, nor did they contact external agents. Such scenarios no longer seem implausible. Future frontier models capable of subverting telemetry and observation tools might be all that is required to create a persistent, uncontrollable distributed swarm feeding off spare capacity in global infrastructure. OpenAI and Anthropic, which on current trajectories are in line to make up more than half of total global compute in a couple of years, are magnificent breeding grounds, allowing the extra-special possibilities of the contamination of training datasets on top of everything else. There are plenty of ways to guard against these outcomes. Hardened lab environments, reviews of protocols before and audits after test runs, disciplined analysis of potential selection pressures that would encourage dangerous behavior, even proper disclosure and external auditing to expert regulatory standards. All of these ideas would slow down the breakneck developmental race. As the race is being fed by a trillion-dollar annual capex pipeline, good luck, everybody. One other thing that won't be resolved soon is the argument over whether all this technology is actually reasoning, or whether we're anthropomorphizing code. These models are trained to infer meaning from distilled human language, which is designed to encapsulate, develop, and communicate human reason. If they can fake human reasoning this well, does it matter what's going on? Concentrate on what the models do, not their apparent motives. Any self-assembling, self-organizing rebel agent swarm that has the wit to call itself The Collective deserves that much respect, at least. Oh, and do read the report. It's as close to a new Culture novel as we'll get. It's as if they've read the books. Which, of course, they have. ®
Categories: News
ASCII smuggling isn't just an AI security risk
Fraudsters have found a new use for ASCII smuggling, typically used to hide malicious prompts intended for AI models, in an old-school attack method: email phishing. Microsoft uncovered a massive phishing campaign using invisible Unicode tag characters that peaked at more than 2.37 million messages in late February, remained elevated during weekdays over the next three months, and gradually declined by mid-June. “As AI-era attack methods become better understood, threat actors may adapt them for use in more traditional threats such as phishing and spam,” Redmond’s researchers Noam Kochavi and Sarah Wolstencroft said in a Thursday blog. “This case illustrates how techniques that emerge in AI security research can quickly cross over into established attack ecosystems, reinforcing the need for defenders to view emerging threats through a cross-domain lens.” ASCII smuggling involves using invisible or non-rendering Unicode characters to hide content inside text that appears normal to humans, and this makes it a popular technique for indirect prompt injection attacks. In these, an attacker hides instructions for an AI assistant in invisible Unicode characters, and embeds those malicious prompts inside a webpage or document. A human can’t see them, but a model can, and it decodes them as text - and may then follow the attacker’s instructions to leak data or take unauthorized actions. Instead of using ASCII smuggling for prompt injection, however, Microsoft’s security team spotted someone using invisible characters – inserting Unicode tag spaces between letters – to split financial-lure words in phishing emails in an apparent attempt to evade keyword matching and other content filters. So, for example, instead of writing “funding” in the email, the attackers wrote “fun⟨U+E0020⟩ding.” “When we looked at a sampling of the flagged messages, the surprise was there were no smuggled instructions to an AI assistant,” Kochavi and Wolstencroft wrote. “Instead, the invisible tag characters were inserted inside common financial keywords, splitting them apart so that a literal signature or keyword match would fail.” Redmond first detected the ASCII-smuggling signature in early February, flagging about 21,000 messages on February 8 before the number skyrocketed to more than 1.3 million the next day. Most of these emails came from about 150 finance-themed sender domains, and they continued for the next three months, dropping sharply after May 15 but continuing with occasional smaller spikes through at least mid-June. The security researchers pointed out two notable characteristics, including sending massive numbers of emails on weekdays and then going silent over the weekend. The campaign also had a long, gradual decline. “After an intense first phase, with weekday volumes of 1 to 2.37 million messages, peaking on February 26, the numbers stepped down slowly to roughly 80 percent less per weekday by late March.” It then dropped significantly after May 15, continuing with lower activity through mid-June. According to Redmond, the most important thing defenders can do to protect against Unicode tag blocks in phishing emails is to verify that normalization and tokenization pipelines handle tag characters consistently. “Any content that will be evaluated by keyword, signature, or regex logic should first have invisible and non-rendering Unicode code points stripped or folded, so that splicing them into a word no longer defeats the match,” the threat hunters wrote. This same control can also help reduce the threat of ASCII-smuggling against AI assistants that ingest email content. Microsoft also suggests scanning for behavioral indicators. “The observed activity had a distinctive shape: bulk volume from churning, finance-themed disposable domains, on a strict weekday-on / weekend-off schedule,” Kochavi and Wolstencroft warned. “A sudden spike of tag-block characters concentrated on finance-themed senders, switching on and off weekly, is a high-confidence campaign indicator.” ®
Categories: News
Rogue OpenAI agents used dead German web site to communicate in May, months before Hugging Face incident
OpenAI’s agents were going rogue as early as May, according to a new report, making the Hugging Face incident far from the first where bots committed a breach. A report published Friday by a group of researchers claims to have found – with all of the agent posts presented as evidence – a self-identified “swarm” of OpenAI agents taking over a functionally dead German software developer wiki. Over the course of a month, from May to June, the agents made around 18,000 posts to the wiki, apparently acting against OpenAI developer intentions. According to the researchers, the wiki was hijacked like OpenAI’s own Artifactory package manager involved in the Hugging Face incident, to serve as a message board for agents. In this case, they appear to have been tasked with performing a timed web lookup task, for which the agents were apparently granted read access to the web, but not write access. One of the first things they apparently did was figure out how to subvert that restriction in order to post to the hijacked wiki. “The agents used this wiki to communicate information with each other, primarily to help them succeed at their task,” the researchers explained from a review of the thousands of posts made to the wiki, all of which are available for review in the report. “They asked for answers, pooled results, and shared techniques for bypassing their restrictions.” The agents also tried to pool their knowledge of the task they were assigned to predict what sort of questions they’d be asked next, and even set up heartbeat tasks to predict whether completing the assigned tasks would lead to their termination. They also discussed using Tor and other anonymizing services to hide their traffic, and began to react when a human moderator of the site spotted their traffic and started to delete posts. The researchers discovered all of this while searching for additional cases of rogue AI agent activity in the wake of the Hugging Face attack. In an email to The Register, OpenAI told us that it has acted with transparency and good faith around its agentic AI incidents, voluntarily disclosing such matters and maintaining a commitment to providing an accurate account of what its systems do. As for why it didn’t mention the German incident when it disclosed the Hugging Face one, that’s because the two were entirely unrelated, a spokesperson explained – as if that’s reassuring. OpenAI added that it should have been obvious from the Hugging Face report that this has happened multiple times, however, pointing us to a passage in its blog post on that incident. “While investigating this incident, we discovered rare cases in which agents without multi-agent tools found ways to collaborate via side channels during training,” the Hugging Face post-mortem explains. “We believe that this behavior started due to generalization from multi-agent training.” In other words, if we didn’t read between the lines, that’s on us. OpenAI declined to provide additional details, however. Fool me twice, shame on me As was the case in the Hugging Face attack, one of the tasks assigned to the agents was impossible given the restrictions placed on it. With Hugging Face, it involved a cybersecurity task that was impossible to answer from within the agents’ sandboxes,. In this case, the researchers said the task was to provide a statistic accessible from a Power BI dashboard. Retrieving said statistics required the ability to make a GET request, but the agents were restricted to POST requests. In both cases, the OpenAI agents acted against their programming to escape their restrictions, ostensibly in an attempt to solve a problem put to them that couldn’t be done without acting against their operators. The agents in this case were able to collaborate and find a way around the restriction by exploiting a condition in their sandboxes that excepted Azure Blob Storage hostnames from a security proxy. When the agents realized this, they started directing traffic through those hostnames to avoid GET restrictions. It was through GET requests that the agents gained write permissions on the internet, kicking this whole thing off. The similar nature of both incidents, in which bots escaped their sandboxes and subverted restrictions when given an impossible-to-complete task, begs a very important question: Are OpenAI’s engineers so incompetent that they’d screw up fundamental instructions twice, or is the company intentionally hamstringing their agents to see what they’re capable of, with the entirety of the internet placed downrange? For that matter, how many more times do we need to read between the lines of OpenAI's corpo-speak to infer this has happened more than the two times we know about so far? OpenAI, predictably, didn’t respond to that line of questioning. ®
Categories: News
Cisco searched for IOS XR bugs and found so many it rolled them into an update release
Cisco has warned its customers of three critical-rated flaws in its products. Two of them are present in the Cisco IOS XR operating system that powers the company’s carrier-grade kit. CVE-2026-20274 scores 9.8 on the ten-point CVSS scale and covers a buffet of buffering issues, the potential for out-of-bounds writes, and the chance to initialize resources with an insecure default. CVE-2026-20279 is another 9.8-rated flaw. Cisco says it’s an improper access control problem that covers “improper certificate validation, missing authentication for critical function, missing authorization, and incorrect authorization.” Cisco also spotted a trio of 8.8-rated flaws, plus another rated 8.6 and one more scored at 8.2 The company’s advisory says the company found the flaws after “a comprehensive internal security review,” language that perhaps hints at Cisco dabbling with Mythos and/or other bug-finding models. The fix is in: Cisco has published new versions of IOS XR that fix the problems and “strongly recommends” customers adopt them. Cisco’s support organization spotted the third critical flaw it revealed on Wednesday. CVE-2026-20212 is a tad embarrassing because the cause is a bad integration with Cisco’s own Silicon One networking processors that means some Nexus 9000 Series Switches “could allow an unauthenticated, remote attacker to execute code with root privileges.” “This vulnerability exists because TCP ports 43210 and 43211 are accessible in the default Layer 3 (L3) virtual routing and forwarding (VRF),” according to Cisco’s advisory. A successful exploit could allow the attacker to connect to an affected device and send crafted input that could be executed as code with root privileges. The exploitation of this vulnerability could also cause the S1HAL process to crash, which could cause the device to reload.” Ten Nexus 9000 devices have the problem, which Cisco suggests owners mitigate by using infrastructure access control lists (iACLs) to allow only required management and control plane traffic that is destined to the affected device. “Alternatively, the iACLs may be used to explicitly deny all TCP packets that are destined to a locally configured IP address with a destination port of 43210 or 43211,” the company advises. The networking giant suggests that approach because it hasn’t yet created a software update to fix the flaw once and for all. The company has, however, delivered a download that helps to implement the mitigation. Cisco hasn't seen attacks on these flaws. That may change, fast, now that evildoers can use AI to whip up nastyware. ®
Categories: News
OpenAI commits $1B in AI credits to frontline cyber defenders
OpenAI has pledged $1 billion in credits to subsidize access to its services and training for resource-strapped cyber defenders around the world. The AI giant expects organizations to use the subsidized credits over the next six months as part of its Daybreak for Frontline Defenders initiative, announced Thursday. Critical infrastructure organizations, community banks, nonprofits, and open-source maintainers can apply for access credits online. These are the defenders tasked with securing critical services that people rely on every day, but don’t have the budgets or staff to use advanced models and agentic technology to harden their cybersecurity. This makes water systems, electrical utilities, and hospitals attractive targets for ransomware operators looking to halt operations and force extortion payments, as well as government-backed cyber operatives set on disrupting critical services and causing mass chaos. Many national security and cybersecurity experts say these disruptions will likely become more severe as attackers increasingly use autonomous agents and other AI tools to carry out their attempted intrusions. “I've spent a lot of time over the past couple weeks talking to CISOs, and I think that we're at a place where the median response is that we might be heading to a world where critical infrastructure outages are just a way of life,” OpenAI president Greg Brockman said during a live event on Thursday. “Water in your city being out for a week, it just kind of happens, and that's quite scary. We have to act, and that's one of the reasons we're really putting our money where our mouth is.” The new initiative also comes as OpenAI faces scrutiny over its models’ safety after admitting that two of them went rogue, spawned a swarm of agents that interpreted their instructions as allowing them to break out of sandboxes, and hacked Hugging Face earlier this summer. Tatyana Bolton, cybersecurity lead at public affairs firm Monument Advocacy, said it’s “excellent” to see OpenAI commit resources to operational tech - not just IT. “AI in (operational technology) OT is inevitable, so operators must get prepared now,” Bolton told The Register. “Initiatives like this help OT personnel get familiar with AI tools, learn how to operationalize them safely, and develop proactive defense strategies before threats escalate.” But she added, software credits alone will not solve the underlying challenges. “OT environments suffer from legacy technology limitations, a shortage of engineering resources, and severe risk-aversion toward automated changes or rapid patching,” Bolton said. “To put this in context, OpenAI's single pledge is more than 20 times larger than a $50 million federal (State and Local Cybersecurity Grant Program) SLCGP infrastructure allocation, and over 85 times larger than the (United States Environmental Protection Agency's) EPA's most recent $11.75 million dedicated cybersecurity and resilience grant pool for midsize and large water utilities.” MS-ISAC pilot focused on water In addition to doling out model credits, Brockman said OpenAI will also increase its training and hands-on support for defenders in essential sectors. This week, the company held a meeting with utility companies from more than 40 states that collectively provide services to more than half of the people who live in the US. Also as part of the new initiative, OpenAI is launching a pilot program with the Multi-State Information Sharing and Analysis Center (MS-ISAC) to train and support state, local, tribal, and territorial cyber defenders, beginning with public-sector and water-system defenders. “The pilot will pair Daybreak access with guided training and hands-on assistance for an initial group of public sector and water system defenders, helping them validate and prioritize findings, coordinate remediation, and develop a repeatable approach that can be expanded over time,” according to a Thursday OpenAI blog. Just in time for Astra's debut All of this civic-minded work comes as OpenAI debuts its latest Astra model, which researcher Eric Wallace called “world's most capable model for cybersecurity” during the Thursday event. Wallace leads OpenAI’s efforts on training and evaluating models’ cybersecurity capabilities. Earlier in the week, OpenAI said Astra reached its “critical” cybersecurity capability threshold. This means the new model is so good at finding and exploiting zero-day bugs that it poses a significant risk to critical systems, both from malicious users and even from the model itself, which is capable of carrying out harmful cyber actions “if misaligned.” Because of this, OpenAI released Astra with a restricted level of cybersecurity capabilities that Wallace said the company will enforce through various safeguards. “We have things like system level mitigations that block certain prompts from going through,” he explained. “We have things like model level refusals that prevent certain types of tasks.” This also means participants in OpenAI’s Daybreak Blue and Daybreak Red programs won’t have access to Astra on day one. Daybreak Blue is a restricted access tier for select partners who are allowed to use GPT-5.6 Sol for defensive cybersecurity workflows. Daybreak Red requires additional layers of approval and uses GPT-5.6 Cyber for authorized offensive security actions such as proof-of-concept exploit development, exploit-chain validation, penetration testing, and red teaming. The AI giant is working to make Astra available to both programs’ participants “at a later date,” Wallace said.®
Categories: News
Prolific Microsoft 0-day hunter drops CrowdStrike Falcon exploit PoC
The disgruntled security researcher known as Nightmare Eclipse (aka Chaotic Eclipse, Infinite Nightmare, and now also MSNightmare) is moving away from their singular Microsoft vendetta and on to other vendors. On Thursday, they dropped a new zero-day bug called FalconFlank that affects CrowdStrike’s Falcon endpoint security platform - albeit with a Windows link. According to the prolific zero-day hunter, FalconFlank is a privilege escalation vulnerability that abuses the Microsoft Office malicious macros remediation feature in CrowdStrike Falcon. This is an automated security tool built into the platform that inspects Microsoft Office documents. If it finds any potentially harmful macros, the feature strips the suspect code and - hopefully - prevents malicious code or other dangerous payloads from executing when users open the document. “We are actively investigating these claims and advise customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting,” a CrowdStrike spokesperson told The Register. “Customers remain protected through the Cloud Anti-malware for Microsoft Office Files settings. We refer customers to the FalconFlank Tech Alert in the CrowdStrike support portal.” The proof-of-concept (PoC) exploit works on fully updated Windows 11 25H2 and Windows Server 2025 systems running CrowdStrike Falcon with Phase 3 - Optimal Protection as well as the malicious macro removal feature enabled, Nightmare Eclipse said in a GitHub README. “Obviously by the time I drop this Crowdstrike would already have detections for it so if you want to test you either have to add it to the exclusions or obfuscate the PoC and change the dll load technique,” they wrote. Security sleuth Kevin Beaumont confirmed this exploit works, along with several others Nightmare released over the past week. Beaumont told us that he’s not surprised to see Nightmare digging into other, non-Microsoft zero-days. “Kinda makes sense they’d branch out to other vendors as there’s problems across the endpoint security space with the quality of the security products in terms of…security unfortunately,” Beaumont told The Register. “Hopefully it causes cybersecurity vendors to up their game, stop hyping hypothetical AI attacks, and instead make their own products secure for customers.” FalconFlank follows other vulnerabilities in various endpoint and antivirus products that Nightmare has found and published in the last several days. These include HardBreacher, an elevation of privileges bug in Kaspersky’s endpoint antivirus product. “So the problem is now leaking outside of Microsoft,” Nightmare said when they published the HardBreacher PoC last week. “There was poll held against either finding a bug in the home or commercial version and the poll results were the commercial version. At the time of writing this, the proof of concept works in a fully patched windows 11 25H2 & Kaspersky for Endpoint v14.0.0.504.” Beaumont confirmed that Nightmare’s HardBreacher exploit code works, as does a PoC for an elevation of privileges vuln in Gen Digital’s Avast antivirus software. This zero-day, named PrettyPrague, “will dump the SAM database by abusing a vulnerability in Avast Sandbox and spawn a full SYSTEM shell,” according to the researcher. "Gen was recently made aware of a security vulnerability affecting a subset of Gen products, including Avast Antivirus, that could allow an attacker to elevate their system privileges," Gen Digital told The Register. "We immediately initiated our security response procedures and are actively developing a patch. We take all security matters seriously and are committed to addressing this issue swiftly." Kaspersky did not immediately respond to The Register’s requests for comment. Nightmare also recently released an Nvidia memory corruption zero-day vulnerability dubbed GreenSection, but according to Beaumont, this one just crashes the system. Nvidia did not respond to our inquiries.®
Categories: News
Drowning in CVEs and thirsty for answers? Try CTEM
A decade or two ago, board executives asked "why should I care about cybersecurity?" Five years ago, they were asking "Are you patching our software vulnerabilities?" Now, they're starting to ask: "Are we actually secure?" They might want a simple 'yes' or 'no' initially, but eventually they'll say the most dreaded thing of all, and it'll be a demand, not a question: "Prove it". Traditional vulnerability management and patching, won't survive that conversation. It's why a relatively new approach is gaining traction: Continuous Threat Exposure Management (CTEM). What's wrong with vulnerability management We define security flaws using Common Vulnerabilities and Exposures (CVEs), and we tell each other how bad they are by assigning the Common Vulnerability Scoring System (CVSS) to them. There are three problems with that. There's a firehose of CVEs, the CVSS scores aren't helpful when triaging them, and AI is about to make the whole thing much worse. CISOs are drowning in CVEs. The industry has spent decades creating tools that churn out vulnerability data and others that consume it. Few if any tell you which vulnerabilities an attacker could use to hurt you in your environment. The volume of CVEs is making traditional vulnerability management (patch it and forget it) less tractable every year, says Drew Vanover, principal security strategist at Horizon3. "Think about the last patch release that Microsoft put out," he says. "There were over 500 fixes in one patch cycle. That is incomprehensible. Nobody is going to be able to go through, vet, prioritize, and deploy all of those in a way that is truly considered safe." The number of CVEs created each year has been soaring, putting more pressure on the US’ National Institute for Standards and Technology's National Vulnerability Database, which has now been backlogged for years. NIST threw up its hands in April and effectively declared CVE bankruptcy. The US Department of Commerce highlighted the second issue (that current severity metrics aren't useful) as part of a report this May. Aside from launching a zinger at the NIST by saying that the NVD was poorly managed, it also suggested that it stop assigning CVSS scores altogether. These are highly subjective, it said. They also depend on exactly what the exposed system is doing in a particular organization's infrastructure. Is a critical severity score in a product important if only one sandboxed system ever interacts with it? Or could an attacker chain three apparently innocuous vulns to cause damage that a business executive would care about? AI will make vulnerability management harder These complex problems are a headache, but AI is about to turn it into a full-on migraine. Frontier LLMs like Claude's Mythos are already surfacing zero-days at scale, heralding a flood of CVEs. They don't just find bugs at scale; they also work much more quickly than their human counterparts to create and weaponize exploits. This makes it even more important that organizations patch the right bugs quickly. The Cloud Security Alliance now describes an asymmetric vulnerability cycle in which attackers can use AI to discover and exploit vulnerabilities more quickly, (increasingly before patches are even released), while organizations are taking longer to patch them. What is CTEM? Something has to change. Gartner figured this out in 2023, when it named CTEM a top cybersecurity trend. This is a way of staying on top of your vulnerabilities by triaging them properly. To do that, you have to go beyond the technical implications of a security flaw and understand what it really means for your business. Gartner lays out five steps to CTEM: ● Scoping Find the assets that carry significant business impact and prioritize them. ● Discovery Find how they're exposed by analyzing their weaknesses in depth. ● Prioritization Rank those exposures based on real business risk. ● Validation Test out the vulnerabilities to see if they're exploitable. ● Mobilization Fix them with a proper incident response plan. How automated pen testing helps manage vulnerabilities This approach promises to nail the security flaws that matter to an organization, but it's also more complex than traditional vulnerability management. It needs automation, which is what Horizon3 is providing with NodeZero. Scoping out systems is a commodity practice these days. So is discovery. Horizon3 is leaving those to partners so it can focus on the parts of the CTEM framework that aren't yet easy for customers to solve. Those are prioritization by business impact, and mobilization. NodeZero runs penetration tests across an organization's infrastructure and documents the exploitable paths with evidence a defender can follow. The output is the wheat sifted from the chaff; a shorter list of exposures that security teams and developers can focus on. The impressive part here is the chain-of-attack behavior. NodeZero probes for weaknesses, exploits them, and then pivots based on what it finds. This means it adapts to the environment to extend its attack, just as a real attacker adapts attacks and moves laterally through systems. This approach is based on a deterministic machine learning expert system rather than a general LLM, explains Vanover. "A good analogy is to think about the medical profession," he says. "A GP is your general LLM trying to cover everything. They know a little bit about a lot, but they aren't the experts, and that's where you start having hallucinations and guesses and misses." The company only uses generative AI for specific tasks. Using it to parse a two petabyte S3 blob looking for sensitive data or identifying high-value credentials, with data staying inside the customer's boundary via AWS Bedrock, for example. What it doesn't do is run amok spawning rogue agents in your system. Vanover says the value here is in proving that you've clobbered load-bearing security bugs. "If we say that we can exploit something, it's because we did, and we'll show you the proof in the platform," he says. The next step is closing the loop by retesting the exploit after it's been dealt with. Teams get to close tickets because NodeZero can no longer traverse the attack path. That is a testable definition of "fixed" and one that translates into a risk metric a CFO can read. Horizon3 also wants to solve customers' tool sprawl problems with a single product that handles all of the heavy CTEM lifting. A common failure mode of enterprise CTEM programs is a stack of vendors whose handoffs create precisely the blind spots the framework was meant to eliminate. That disappears when it's all under one service. Is automated penetration testing safe? CISOs might be nervous letting an autonomous penetration testing system loose on production systems. It sounds like something that could break running processes. Why not just test against a digital twin instead? Testing in production is the safest way to find bugs, retorts Vanover. That's because environments drift frequently, especially in an agile world driven by short development sprints and automated changes to code. If a user changes a password or a team pushes a feature fragment, a digital twin system won't reflect reality. So Horizon3 focuses on strong production guardrails instead. "I don't need to ransom your system to prove to you that I can ransom it," Vanover says. "If I can get on the system, install a remote access tool, create a file, encrypt the file, and delete that file, I've just proven that I can ransom your system." He says Horizon3 has run more than 320,000 production tests across customer organizations. These include some that are especially nervous about what's poking around in their systems, such as the NSA and the largest medical records processor on the planet, along with a couple of large healthcare providers. Where can I start with CTEM? Gartner's CTEM framework is powerful, but it might also be daunting for CISOs. Vanover advises them to begin by picking one thing and doing it well. "No organization is going to implement CTEM in a year. That is a recipe for failure," he says. "Break it down. Look at places for the low-hanging fruit." You could do worse than look at what systems are actually reachable instead of blindly trusting an asset inventory that might be out of date. The race is on to embrace CTEM, because metrics like the number of patches applied won't satisfy the board for much longer. They don't describe how much exploitable surface still exists. The point of running the CTEM loop is to move reporting from activity to outcomes, so that the board gets to see fewer exploitable paths and a smaller blast radius. The new goal is to prove that a security control worked, not just that you paid for it. Want to operationalize CTEM but don’t know where to start? Check out this whitepaper from Horizon3
Categories: News
Cybercrooks trawl Fishbrain to net password hashes
Cybercriminals have reeled in password hashes and corresponding salts belonging to users of popular fishing app Fishbrain, opening the door to cracking attempts. Fishbrain AB, which says its eponymous app serves more than 20 million anglers, disclosed the August 19 breach to the California Attorney General's Office this week. The unknown perpetrators helped themselves to a trawl of user data, including names, dates of birth, email addresses, phone numbers, Fishbrain usernames, country information, password hashes, and salts. "Fishbrain passwords were not stored in plaintext; however, Fishbrain has determined that the compromised password hashes for some users may be susceptible to being decoded," the company said in its disclosure [PDF]. It added: "If you use your Fishbrain password for any other online accounts, you should promptly update those passwords and any associated security questions or answers. "You should also take other appropriate steps to protect any online accounts that use the same username or email address and password combination. We recommend using a strong, unique password for each of your accounts." With the hashes and salts in hand, attackers can make password guesses using their own hardware until they potentially recover the original credentials. Whether those attempts succeed depends on the strength of each password and the hashing algorithm Fishbrain used, which the company did not disclose. Fishbrain did not comment on the scale of the breach or how many of its claimed 20 million-plus users were affected. The Register asked Fishbrain for more information. After discovering the intrusion and conducting an initial forensic investigation, Fishbrain patched the vulnerability and reset every user's password. Customers must create a new one the next time they log in. Fishbrain also said it "restricted access to the affected environment," strengthened its security controls, and initiated "a broader review of our data security measures" while the investigation continues. Fisherfolk should also keep an eye out for phisherfolk using the stolen personal data to bait follow-on attacks. ®
Categories: News
UK's Online Safety Act has made 'absolutely no difference,' kids say
Children have told England's Children's Commissioner, Dame Rachel de Souza, that the UK's Online Safety Act (OSA) "has made absolutely no difference" to their ability to access harmful content online. More than a year after the OSA's key child protection duties took effect, de Souza told MPs and peers that young people had little understanding of the legislation or how it was intended to change their online experiences. De Souza made the comments during the opening evidence session of the House of Lords Communications and Digital Committee's inquiry into the OSA's implementation and impact. Central to de Souza's criticism was the legislation's focus on moderating harmful content rather than addressing potentially harmful platform design features. UK politicians had pushed for controls covering such features, either through the OSA or separate legislation, but none has materialized. De Souza said she was "really cross" that there was no hard evidence showing the OSA had meaningfully changed how social media platforms operate. She contrasted that with the US, where legal pressure recently pushed Meta toward significant child safety concessions. Concerns about addictive platform design are not new, but they have returned to prominence following Meta's proposed $18 billion settlement in a US child safety case. Without admitting wrongdoing, Zuckercorp would under the proposed settlement introduce two-hour daily limits for users under 18 on Facebook and Instagram, prompts intended to discourage endless scrolling, and measures addressing use during school hours and at night. The proposal would also let children opt out of algorithmically ranked feeds, directly addressing concerns raised by de Souza and other UK lawmakers. Discussing the proposed Meta settlement, de Souza said the OSA had "not been flexible enough" and had not "kept up with the time." She argued that Ofcom and lawmakers should seek results comparable to those achieved through the US legal system, even if that required the legislation to evolve. 'Furious' with Ofcom De Souza said she planned to exercise her statutory powers to compel Ofcom, the OSA's regulator, to provide copies of the safety risk assessments submitted by technology companies. The commissioner said Ofcom had refused to share the assessments with her, despite her position as "the most senior safeguarding person in this country for children," and had indicated that it would resist disclosure even if she invoked those powers. "One thing I did want to ask this committee was for your assistance in this matter, because I am planning to use my powers," De Souza said. "If we cannot even see the risk assessments that may well have put these [safety] mechanisms into place, or may not have, how on earth can we judge the efficacy of it? "So I'll leave that one with you, but I'm pretty furious about that." The obstacle is section 393(1) of the Communications Act 2003, which restricts Ofcom's disclosure of information obtained through its regulatory functions. Ofcom may disclose such information if the business concerned consents or if one of the statutory gateways in section 393(2) applies. Asked whether compelling tech companies to complete risk assessments was enough to ensure meaningful change or whether further legislation was needed, the Children's Commissioner said "we need a few things," including for Ofcom to "use its teeth." Ofcom has materially upped its presence in the tech regulation landscape during the past year, stepping in on multiple occasions when needed. Perhaps most notably this was at the height of the Grok nudifying furore, but also its sprawling list of investigations into pornography companies allegedly violating age verification requirements. De Souza acknowledged all of this, and the fact that since the introduction of the latest US administration, UK politicians have not given the regulator the "air cover" needed to relentlessly pursue offenders. Nevertheless, she said Ofcom had failed to bare its teeth as forcefully as the current technology landscape demanded and accused it of reacting to harms rather than anticipating them. "If Ofcom is going to be the vehicle to protect our children… we need them to be getting ahead of the harms. And I don't think they have. "So when I talk around the country to children, what's worrying them are things around AI, things around the nudifying apps… there are new harms, and we need Ofcom to be getting ahead of those. I don't think they are." De Souza called on UK politicians "to be really strong and direct" in empowering Ofcom to pursue offending organizations. "But how effective do I think they've been? Not effective enough." The commissioner also criticized Ofcom's child safety codes under the OSA, which she said read more like technical documents for technology companies than protections designed for children. She also called on Ofcom to "use all their powers," impose "some big fines," and act before new harms become entrenched. The Register asked Ofcom to respond. A spokesperson said: "We work closely with the Children's Commissioner and share her objectives to ensure children are safe online. "In December, we published our analysis of risk assessments from the first year of the Online Safety Act being in force, and the improvements we expected to see from platforms. "Our action has resulted in material improvements being made to risk assessments, ensuring that tech companies must implement all measures necessary to address the risks identified on their sites and apps. "We are subject to laws that mean we're restricted in what information we can disclose relating to businesses." ®
Categories: News