The Register
Zombie Microsoft bugs rise from the dead, pave way for crims and ransomware scum
Crooks are exploiting four Microsoft vulnerabilities - one patched 14 years ago and another tied to ransomware activity - according to America's lead cyber-defense agency, which on Monday gave federal agencies two weeks to patch them.…
Fake Linux leader using Slack to con devs into giving up their secrets
Imagine getting asked to do something by a person in authority. An unknown malware slinger targeting open source software developers via Slack impersonated a real Linux Foundation official and used pages hosted on Google.com to steal developers' credentials and take over their systems.…
Booking.com warns reservation data may have checked out with intruders
Booking.com is warning customers that their reservation details may have been exposed to unknown attackers, in the latest reminder that the travel giant still can't quite keep a lid on the data flowing through its platform.…
Gym giant Basic-Fit confirms data on a million members stolen in cyberattack
Basic-Fit, Europe's largest gym chain, has confirmed data including the bank details of around a million customers was stolen from its systems.…
Rockstar Games gets a taste of grand theft data amid ShinyHunters threat of 'Pay or leak'
ShinyHunters is back, this time pinning Rockstar Games to its leak site and claiming it didn't so much hack its way in as walk through a door someone else left wide open.…
NHS pays £46K to prep next Microsoft licensing round
NHS England is spending £46,000 on "benchmarking" as it gears up for what looks like the next round of negotiations behind one of the UK public sector's biggest software deals.…
China wants AI to prepare school lessons and mark homework
Asia In Brief China’s National Data Administration last Friday published its action plan for AI in education which calls for upskilling of the nation’s citizens to ensure they can put the technology to work.…
Anthropic's mysterious Mythos AI threatens to upend the infosec world
Kettle Anthropic dropped a doozy on us this week with the launch of Mythos, an AI model it says is able to find and exploit zero-day vulnerabilities with a shocking level of ability. …
Two different attackers poisoned popular open source tools - and showed us the future of supply chain compromise
FEATURE Two supply chain attacks in March infected open source tools with malware and used this access to steal secrets from tens of thousands – if not more – organizations. We won't know the full blast radius for months.…
Hungarian government creds left in the safe hands of 'FrankLampard'
Hungary's government has discovered the hard way that the biggest threat to national security might just be its own password choices.…
CPUID site hijacked to serve malware instead of HWMonitor downloads
Visitors to the CPUID website were briefly exposed to malware this week after attackers hijacked part of its backend, turning trusted download links into a delivery mechanism for something far less welcome.…
Project Glasswing and open source software: The good, the bad, and the ugly
Opinion Anthropic describes Project Glasswing as a coalition of tech giants committing $100 million in AI resources to hunt down and fix long-hidden vulnerabilities in critical open source software that it's finding with its new Mythos AI program. Or as The Reg put it, "an AI model that can generate zero-day vulnerabilities."…
Britain seeks views before it drops the hammer on signal jammers
The UK government is seeking views on radiofrequency jammers as it prepares legislation to ban the controversial devices.…
Unpacking AI security in 2026 from experimentation to the agentic era
Webinar Promo 2025 was the year of AI experimentation. In 2026, the bills are coming due. AI adoption has moved from isolated pilots to autonomous, enterprise wide deployment, bringing with it a sophisticated new generation of security challenges.…
Crypto? Huh. Good gawd y'all, what is it good for? $45M in this case
US, UK, and Canadian law enforcement Thursday said that they disrupted a $45 million global cryptocurrency scam, freezing $12 million in stolen funds and identifying more than 20,000 cryptocurrency wallet addresses linked to fraud victims across 30 countries.…
'Several dozen' high-value corporations hit by new extortion crew in helpdesk phishing spree
A new extortion crew has targeted “several dozen high-value” corporations through phishing and helpdesk social-engineering, according to Google.…
Chevin pulls the handbrake on FleetWave software after security scare
A cybersecurity incident has knocked FleetWave into a "major outage" across the UK and US after Chevin Fleet Solutions pulled parts of its SaaS platform offline and left customers scrambling for answers.…
Months-old Adobe Reader zero-day uses PDFs to size up targets
Hackers have been quietly exploiting what appears to be a zero-day in Adobe Acrobat Reader for months, using booby-trapped PDFs to profile targets and decide who's worth fully compromising.…
Microsoft locks out VeraCrypt and WireGuard devs, blames verification process
Microsoft says that it will work on how it communicates with developers after two leading open source figures were suddenly locked out of their accounts, leaving them unable to sign updates.…
Security researchers tricked Apple Intelligence into cursing at users. It could have been a lot worse
Apple Intelligence, the personal AI system integrated into newer Macs, iPhones, and other iThings, can be hijacked using prompt injection, forcing the model into producing an attacker-controlled result and putting millions of users at risk, researchers have shown.…