The Register
Kensington and Chelsea confirms IT outage was a data breach after all
Kensington and Chelsea Council has admitted that data was quietly lifted from its systems during last week's cyber meltdown, confirming that the outage was not just an IT faceplant but a bona fide data breach.…
FTC schools edtech outfit after intruder walked off with 10M student records
US edtech provider Illuminate Education just got dinged by the Federal Trade Commission for allegedly failing to keep an attacker from pilfering data on 10 million students.…
India demands smartphone makers install a government app on every handset
India’s government has issued a directive that requires all smartphone manufacturers to install a government app on every handset in the country and has given them 90 days to get the job done – and to ensure users can’t remove the code.…
Stealthy browser extensions waited years before infecting 4.3M Chrome, Edge users with backdoors and spyware
A seven-year malicious browser extension campaign infected 4.3 million Google Chrome and Microsoft Edge users with malware, including backdoors and spyware sending people's data to servers in China. And, according to Koi researchers, five of the extensions with more than 4 million installs are still live in the Edge marketplace.…
Four arrested in South Korea over massive IP camera snooping spree
Cybercrime suspects and offenders across three continents have been rounded up this week, with cases spanning hacked IP cameras in South Korea, evil twin Wi-Fi traps in Australia, and a dark web drug empire in rural England.…
Dutch study finds teen cybercrime is mostly just a phase
Young threat actors may be rebels without a cause. These cybercriminals typically grow out of their offending ways by the time they turn 20, according to data published by the Dutch government.…
South Korea's answer to Amazon admits breach exposed 33.7M customers
South Korean retail behemoth Coupang has admitted to a data breach that exposed the personal details of 33.7 million customers, turning the company's famed "Rocket Delivery" logistics empire into an express shipment for personal information.…
French Football Federation faces own-goal after club software data breach
The French Football Federation (FFF) has conceded that attackers broke into its member management software using a compromised account, scoring a match sheet's worth of player data in the process.…
Google and Apple ordered to stop fake government TXTs
Asia in Brief Singapore’s government last week told Google and Apple to prevent fake government messages.…
Swiss government says give M365, and all SaaS, a miss as it lacks end-to-end encryption
Infosec In Brief Switzerland’s Conference of Data Protection Officers, Privatim, last week issued a resolution calling on Swiss public bodies to avoid using hyperscale clouds and SaaS services due to security concerns.…
PostHog admits Shai-Hulud 2.0 was its biggest ever security bungle
PostHog says the Shai-Hulud 2.0 npm worm compromise was "the largest and most impactful security incident" it's ever experienced after attackers slipped malicious releases into its JavaScript SDKs and tried to auto-loot developer credentials.…
Brit telco Brsk confirms breach as bidding begins for 230K+ customer records
British telco Brsk is investigating claims that it was attacked by cybercriminals who made off with more than 230,000 files.…
GrapheneOS bails on OVHcloud over France's privacy stance
French cloud outfit OVHcloud took another hit this week after GrapheneOS, a mobile operating system, said it was ditching the company's servers over concerns about France's approach to digital privacy.…
TryHackMe races to add women to Christmas cyber challenge roster after backlash
Cybersecurity training provider TryHackMe is scrambling to recruit women infosec pros to help with its Christmas challenge following backlash concerning a lack of gender diversity.…
OBR drags in cyber bigwig after Budget leak blunder
The Office for Budget Responsibility (OBR) has drafted in former National Cyber Security Centre (NCSC) chief Ciaran Martin to sniff out how its Budget day forecast wandered onto the open internet before the Chancellor had even reached the dispatch box.…
UK digital ID plan gets a price tag at last – £1.8B
The UK government has finally put a £1.8 billion price tag on its digital ID plans – days after the minister responsible refused to name a figure.…
Korean web giant Naver acquired crypto exchange Upbit, which reported a $30m heist a day later
South Korean web giant Naver has had an interesting week, after it acquired a cryptocurrency exchange that the next day revealed it had suffered a serious cyberattack.…
Zendesk users targeted as Scattered Lapsus$ Hunters spin up fake support sites
Scattered Lapsus$ Hunters may be circling Zendesk users for its latest extortion campaign, with new phishing domains and weaponized helpdesk tickets uncovered by ReliaQuest.…
OpenAI cuts off Mixpanel after analytics leak exposes API users
OpenAI says API users may be affected by a recent breach at its former data analytics provider, Mixpanel.…
FCC sounds alarm after emergency tones turned into potty-mouthed radio takeover
Malicious intruders have hijacked US radio gear to turn emergency broadcast tones into a profanity-laced alarm system.…