The Register

Subscribe to The Register feed
Biting the hand that feeds IT — Enterprise Technology News and Analysis
Updated: 1 hour 5 min ago

Vibe coding upstart Lovable denies data leak, cites 'intentional behavior,' then throws HackerOne under the bus

3 hours 34 min ago
A lesson in how not to respond to vulnerability reports

Vibe-coding platform Lovable is pooh-poohing a researcher’s finding that anyone could open a free account on the service and read other users' sensitive info, including credentials, chat history, and source code. However, the company’s story keeps changing: First it attributed the publicly exposed info to "intentional behavior" and "unclear documentation," then threw bug-bounty service HackerOne under the bus.…

Categories: News

Claude Desktop changes app access settings for browsers you don't even have installed yet

Mon, 20/04/2026 - 20:56
Installation and pre-approval without consent looks dubious under EU law

One app should not modify another app without asking for and receiving your explicit consent. Yet Anthropic's Claude Desktop for macOS installs files that affect other vendors' applications without disclosure, even before those applications have been installed, and authorizes browser extensions without consent.…

Categories: News

Scot becomes second Scattered Spider-linked crook to plead guilty in US

Mon, 20/04/2026 - 18:22
Tyler Buchanan admits role in scheme that stole at least $8 million in virtual currency

A Scottish man linked to the Scattered Spider cybercrime crew has pleaded guilty in the US to a phishing and SIM-swap scheme that stole at least $8 million in cryptocurrency.…

Categories: News

Microsoft releases Windows Server update fix to fix its April update fixes

Mon, 20/04/2026 - 14:15
Out-of-band or out of control?

Microsoft has pushed out an out-of-band update to address the restart loop that hit some Windows Server devices after its April update.…

Categories: News

Next.js developer Vercel warns of customer credential compromise

Mon, 20/04/2026 - 08:31
Blames outfit called Context.ai, which reckons an agentic OAuth tangle caused the incident

Vercel, the company that created the open source Next.js web development framework, has a data leak that led to compromise of some customer credentials, and blamed an outfit called Context.ai for the mess.…

Categories: News

Just like phishing for gullible humans, prompt injecting AIs is here to stay

Mon, 20/04/2026 - 00:00
Aren't we all just prompting tokens of linguistic meaning and hoping the other person isn't bullshitting us?

kettle  It's a week of the year, which means there's been the discovery of yet another prompt injection attack that will force supposedly well-guarded AI bots to spill secrets by asking the right way. …

Categories: News

I meant to do that! AI vendors shrug off responsibility for vulns

Sun, 19/04/2026 - 12:07
Passing the buck, and the blame, down the road shows lack of AI companies' maturity

OPINION  AI vendors: "You need to use AI to fight AI threats (and do everything else in your corporate IT environment)." Also AI vendors: "That's not a security flaw; it's working as intended."…

Categories: News

CISA tells feds to patch 13-year-old Apache ActiveMQ bug under active attack

Fri, 17/04/2026 - 18:09
Bug hiding in plain sight for over a decade lands on KEV list

CISA is sounding the alarm on a newly-exploited Apache ActiveMQ bug, ordering federal agencies to patch within two weeks as attackers circle a flaw that's been quietly lurking for more than a decade.…

Categories: News

Opsec oopsie: Dutch navy frigate location outed by mailing it a Bluetooth tracker

Fri, 17/04/2026 - 17:31
Or, how public information and a €5 tracker exposed an avoidable opsec lapse

Militaries around the world spend countless hours training, developing policies, and implementing best operational security practices, so imagine the size of the egg on the face of the Dutch navy when journalists managed to track one of its warships for less than the cost of some hagelslag and a coffee.…

Categories: News

Locked-out iPhone user tells The Reg that Apple is scrambling to fix character flaw passcode bug

Fri, 17/04/2026 - 11:00
University student says he plans to move to Android, but concedes iOS engineers acting fast

Apple is finally working on a fix for a bug that has locked some users out of their iPhones for months, The Register understands.…

Categories: News

Claude Opus wrote a Chrome exploit for $2,283

Fri, 17/04/2026 - 08:02
Pause your Mythos panic because mainstream models anyone can use already pick holes in popular software

Anthropic withheld its Mythos bug-finding model from public release due to concerns that it would enable attackers to find and exploit vulnerabilities before anyone could react.…

Categories: News

Anthropic won't own MCP 'design flaw' putting 200K servers at risk, researcher says

Thu, 16/04/2026 - 23:45
Bug or feature?

A design flaw – or expected behavior based on a bad design choice, depending on who is telling the story – baked into Anthropic's official Model Context Protocol (MCP) puts as many as 200,000 servers at risk of complete takeover, according to security researchers.…

Categories: News

North Korea targets macOS users in latest heist

Thu, 16/04/2026 - 19:20
Social engineering: 'low-cost, hard to patch, and scales well'

North Korean criminals set on stealing Apple users' credentials and cryptocurrency are using a combination of social engineering and a fake Zoom software update to trick people into manually running malware on their own computers, according to Microsoft.…

Categories: News

Americans who masterminded Nork IT worker fraud sentenced to 200 months behind bars

Thu, 16/04/2026 - 16:13
Fortune 500 companies and one US defense contractor got taken for $5m in four-year scam

Two Americans have been jailed for a combined 200 months for helping North Korea generate $5 million through fraudulent IT worker schemes.…

Categories: News

Git identity spoof fools Claude into giving bad code the nod

Thu, 16/04/2026 - 13:57
Forged metadata made AI reviewer treat hostile changes as though they came from known maintainer

Security boffins say Anthropic's Claude can be tricked into approving malicious code with just two Git commands by spoofing a trusted developer's identity.…

Categories: News

Textbook titan McGraw Hill on ransomware crew's reading list after 13.5M records exposed

Thu, 16/04/2026 - 12:49
Publisher claims misconfigured Salesforce-hosted page leaked data

Textbook giant McGraw Hill has landed on a ransomware crew's leak site after an alleged Salesforce-linked misconfiguration spilled 13.5 million records into the wild.…

Categories: News

Microsoft announces product it doesn't want you to buy: Extended security updates for old Exchange, and Skype for Biz

Thu, 16/04/2026 - 11:01
Just migrate already, would you? But if you can't, Redmond will take your cash

Microsoft will keep delivering security updates for old versions of Exchange Server and Skype for Business Server, after admitting that some customers aren't ready to make the move to newer products.…

Categories: News

Server-room lock was nothing but a crock

Thu, 16/04/2026 - 09:00
Your cybersecurity is only as good as the physical security of the servers

PWNED  Welcome back to Pwned, the column where we immortalize the worst vulns that organizations opened up for themselves. If you’re the kind of person who leaves your car doors unlocked with a pile of cash in the center console, this week’s story is for you.…

Categories: News

Google Chrome lacks protection against one of the most basic and common ways to track users online

Thu, 16/04/2026 - 01:28
Browser fingerprinting is everywhere

Google markets its Chrome browser by citing its superior safety features, but according to privacy consultant Alexander Hanff, Chrome does not protect against browser fingerprinting – a method of tracking people online by capturing technical details about their browser.…

Categories: News

Anthropic's Project Glasswing CVE tally is still anyone's guess

Wed, 15/04/2026 - 22:33
Like the majority of the companies participating, it remains a mystery

Last week, Anthropic surprised the world by declaring that its latest model, Mythos, is so good at finding vulns that it would create chaos if released. Now, under the title of Project Glasswing, over 50 selected companies and orgs are allowed to test the hyped up LLM to find security holes in their own products. But just how many problems have they really discovered?…

Categories: News

Pages