Cisco searched for IOS XR bugs and found so many it rolled them into an update release Three critical vulns demand your attention, one a make-me-root mess in Nexus 9000 Series Switches that you can mitigate, not fix
OpenAI commits $1B in AI credits to frontline cyber defenders Daybreak program brings subsidized models, training, and support to under-resourced teams
Cybercrooks trawl Fishbrain to net password hashes Armed with password hashes and salts, attackers could already be kraken those creds
UK's Online Safety Act has made 'absolutely no difference,' kids say Children's Commissioner also furious with Ofcom over a string of failures
Terminated employee cost company hundreds of thousands of dollars because nobody revoked access They had more access than the average Joe, and IT didn't track what needed to be cut off
To keep the AI hacking genie bottled up, try one-way networks Sandboxes, permissions, and VMs aren't enough to keep frontier models at bay. "Data diodes" might do the job
Claude Mythos only model to complete full cyber kill chain, experts say Cyber Weapon Index finds AI attacks 'imminent'
AI agents carried out every step of this ransomware attack – then left the victim an 80-page security audit Adding insult to injury
SonicWall's SMA1000 boxes under active attack again Miscreants use chained zero days to pwn boxen as third-party SOCs say further attacks 'almost certain'
Legacy Lenovo login opens 5,000 Dropbox accounts to attackers Cloud storage biz severs old integration and urges victims to reset credentials
UK cyber bill targets AI users, not the vendors building it Ministers reject proposed red lines and emergency shutdown powers, pointing instead to voluntary safeguards
Cops, CrowdStrike disrupt Sality botnet by poisoning the network and diverting into sinkholes 23-year-old botnet down
Another Artifactory CVE under attack by AI agents or humans Unauthenticated intruders can mint admin tokens, and exposed servers are already being hit
Attacker stole a METR API key, used $600K worth of credits, and no one noticed for weeks The model provider gave METR the credits for free. An actual customer would not have been so lucky
Firefox helps iPhone users bypass ads on web sites while making money showing its own ads Baked-in Firefox ad blocking on iOS begins rolling out slowly today, and is off by default
Anthropic pledges to try harder to keep models under control, asks partners to chip in Security ... this time it will be different
The Gentlemen come calling as Nutex confirms sensitive data theft Ransomware crew threatens publication while healthcare biz assesses which records escaped
33-hour BGP hijack of Softaculous traffic prompts security scramble Hosting software vendor tells customers to reset credentials and hunt for malicious packages
Healthcare cyberattacks hit pacemakers and millions of patient records McKesson admits breach as ShinyHunters demands $55.2M
OpenClaw 2.0 pours glitter on slow-burning security dumpster fire Making installation easier and putting a new wrapper on the interface while leaving most of the security to users is a recipe for more trouble with the popular agent harness
Attack hides malware in PNGs and drops custom reverse tunnel on victims' machines Next-level ClickFix wave sets off multi-stage attack chain
Anthropic cracks down on hijacked user accounts mining AI tokens Commodity malware steals authenticated sessions, letting thieves freeload on victims' paid usage
Turns out Brits would quite like their private messages to stay private Polling finds two-thirds don't trust this government, or any future one, with access to their encrypted chats
Researcher shows how Claude Code can be tricked simply by asking it to summarize a website More prompt-injection hijinks from wunderwuzzi
US government snitch-finder pleads guilty to leaking state secrets to foreign spies The IT specialist began contacting a foreign government within days of being assigned to the DIA’s Insider Threat Division
CISA: Most exploited vulnerabilities should have been eradicated decades ago Organizational culture and systemic gaps in Secure by Design adoption blamed for sorry state of affairs
Industry that built the problem offers to sell you the solution 100+ tech giants warn AI attacks are coming, skip the part where they pay for defenses
Print management outfit PaperCut is under 0-day attack, and it’s drawing customers’ blood The fix is either an unvalidated and unofficial emergency patch or taking the server offline
Australian cops cuff alleged TeamPCP masterminds Alleged crew behind the Shai-Hulud worm and other supply chain attacks nabbed with help from the FBI
CRPx0 hacking service for dummies claims victim count more than quintupled It's 'built to be operated by a human with no technical background'
AI girlfriend review site's secrets were exposed to the world for three weeks Even testing and staging sites need protection from prying eyes
ATF responds to 'major' cybersecurity incident after ransomware gang's claims US Justice Department investigating the breach
Cybercrooks jet off with Manchester Airports Group customer data UK’s largest airport operator believes 8.7 million customers affected
Nuisance-call blocker fined £190k for being a nuisance caller Elderly Aids made 758,000 unwanted calls a year selling gear to stop unwanted calls
FBI seizes hacking tools it says China used to attack NASA, DOE, US Senate and other critical networks Beijing's botnets busted
OpenAI explains how its naughty AI agents attacked Hugging Face Biz describes its act of automated irresponsibility as 'a warning shot'
More than 100 water systems were hit in July cyberattacks 'These are test runs for a larger-scale attack'
Boston Scientific discloses 'global disruption' in ongoing cyberattack No timeline to restore IT systems as probe remains ongoing
Carhartt data breach affects 12.9M, half of what ShinyHunters claimed One AI and two trained eyes delved into the heavily padded leaks
You could've applied all 1,449 Oracle patches and still been hit by this attack Attackers now ready to exploit how things work, rather than just break them, says Oracle support expert
CISA slaps its tightest three-day patching deadline on perfect-10 Oracle flaw Disclosed in January and honeypots buzzed soon after, CISA says it’s finally time for the USG to plug the gap
Crooks push Mac malware through fake OpenAI Codex ads Sponsored search results lead developers straight into a ClickFix malware trap
You don't want this Sleepwalker backdoor on your Windows machine Its own command language, 23 instructions - signs point to 'well-resourced operation rather than an opportunistic one'
Browser fingerprint tool shows how easy you are to track using the latest sneaky tricks Glassbox dev admits he had some help from Claude to build locally running tool
Iran-linked cyberattack shut down a UK power plant No risk to wider energy system, government tells The Reg
ShinyHunters and ReliaQuest trade blows over claimed breach Attackers took a look at an employee's identity dashboard, but security firm says that's as far as they got
AliExpress accused of fingerprinting shoppers with silent audio trick that also muted a dev's headphones Sawtooth waves you can't hear still mess with your Bluetooth. Firefox and Brave say they've got you covered
$1T investment giant Apollo breached after social engineering attack Hackers spent four days inside the org's cloud platforms after apparently talking their way in
Security vets rally around $4 paper password books for sale in Australia Once shunned by the IT crowd, pen-and-paper password vaults are getting the love they deserve in 2026
If you're not using AI to attack your own systems, your adversaries will Agents are also the new attack surface - cue defenders' existential angst
Homeland security cybercops say patch TrueConf (Russia's Zoom) if you're using it Ukrainian hacktivists exploiting the bugs, but TrueConf's reach stretches well beyond home turf
SickKids children’s hospital bandages up careers website after intruder breaks in Toronto org says it wasn’t the only one to be affected by the third-party software vulnerability
Hackers poison popular Rust crates to steal developers' credentials Malicious updates turned routine builds into a delivery system for infostealer malware
$10K phishing kit claims it can plant rogue passkeys for persistent access to pwned accounts Seller's demos show a browser-in-the-middle attack adding credentials seconds after authentication
Microsoft sounds alarm over perfect-10 Entra ID flaw Redmond says the cloud identity bug is already fixed
Cisco bug severity warning reads like Olympic gymnastics scores: 10, 10, 9.9, 9.6, and 7.5. Secure Workload Software has five nasty flaws and even SaaS users have updates to install
Russian snoops add OAuth abuse to targeted phishing campaigns Don't click on that State Department meeting invite
Researcher tricks Apple’s Find My into sharing location data with Linux Clever protocol wrangling gets iBiz-only people tracking working on a non-iGadget
Ransomware crook poses as recovery firm to steal payments from fellow extortionists Because apparently even ransomware gangs can't trust the people they do business with
Grok chat duped into swallowing injected instructions A spoonful of encryption helps the malware go down
French tax authority says break-in exposed data of 600K, including some private messages Stolen details range from contact information to household finances and withholding rates
AI agent suggested installing a malware package. Engineer almost took its advice Fortunately, the company had a policy of checking source code on GitHub first
'Not a theoretical risk,' feds warn as attackers use AI-made code to hack critical infrastructure controllers 'It is an active threat'
ICE boss to agents: Leave the Meta spy glasses at home 'Personally owned body-worn cameras are prohibited,' ICE tells The Reg. Because the last thing DHS needs is more proof of misconduct
Flock surveillance backlash mounts as fiendish Halloween plans circulate CEO apologizes for police misuse as activists call for vandal action against license plate cameras
Comcast gives its Wi-Fi motion detector a security makeover Rebranded feature promises household alerts without video, but mind the small print