More JFrog Artifactory bugs under attack, and all 3 have patches security If you're waiting for a sign to upgrade to a fixed version: this is it Cyber-crime11 Sep 2026 | 1
AT&T store worker gets 16 months inside for SIM-swap side hustle cyber-crime Phone shop staffer claimed he was paid less than $4,000 for attacks leading to combined intended losses of $600,000 Cyber-crime11 Sep 2026 | 3
Ukrainian lawyer's second career as a Conti coder earns him 4 years behind bars CYBER-CRIME Swapping legal work for malware development ended in extradition and a guilty plea Cyber-crime11 Sep 2026 | 7
EU's Cyber Resilience Act starts the 24-hour vulnerability clock Security Manufacturers must now disclose actively exploited flaws and severe security incidents through ENISA's new reporting platform Security11 Sep 2026 | 5
Latest Anthropic horror story chills with tales of kamikaze drone swarms and bioweapons research security Everyone from ShinyHunters to Russian freelancers is in on the illicit model fun AI and ML10 Sep 2026 | 24
Watch out: Apple timepiece can grab snippets of conversation without both speakers' consent SECURITY War is peace. Freedom is slavery. Privacy is surveillance Security10 Sep 2026 | 45
Hundreds of AI agents helped PaperCut attacker hit 395+ orgs, and some went off script security Human operator: don't touch CIS orgs. AI agents: look a squirrel! Cyber-crime10 Sep 2026 | 7
ShinyHunters expose 6.4M in attack on medical supplier McKesson Security Have I Been Pwned logs leaked records spanning patients, staff, and providers Security10 Sep 2026 |
Trezor, BitBox users targeted in newsletter phishing spree cyber-crime Attackers exploit legitimate mailing channels to demand crypto wallet backups Cyber-crime10 Sep 2026 | 6
Dental contractor set up secret account with access to 4,000 patient records then left the company SECURITY Toothless security Security10 Sep 2026 | 19
Anthropic reveals fourth likely crime committed by its AI ai and ml Claude's Felony Bench rap sheet is now as long as OpenAI's AI and ML09 Sep 2026 | 39
Novel Blue Moon kit targeting Chrome and Windows reflects new reality of AI-driven exploits Security Mind the patch gap, please and thank you Research09 Sep 2026 | 1
Serial Microsoft 0-day hunter drops yet another Defender exploit security A bypass of a bypass of a bypass Security09 Sep 2026 | 20
Cryptocrook ringleader, 22, who met crew on Minecraft admits role in $245M heist cyber-crime Stolen funds bought mansions, private jets, and supercars – now he faces up to 20 years Cyber-crime09 Sep 2026 | 16
WeChat worm could pwn a friend before they even answered the call Security Calif says AI helped turn a VoIP memory bug into cross-platform RCE before Tencent shut it down Security09 Sep 2026 | 1
Security boffin claims airport group left API keys in client-side JavaScript for four years cyber-crime Researcher believes overprivileged Iterable creds exposed 8.8M customer records – and could have enabled mass deletion Cyber-crime09 Sep 2026 | 16
Microsoft breaks Patch Tuesday record with 974-CVE deluge security Adobe also brought goodies to the patch party and they deserve immediate attention Security09 Sep 2026 | 25
OpenAI's Artifactory opened covert data-stealing channel alongside Hugging Face attack Security Researchers disclosed the cross-account trick the same day rogue agents exploited another zero-day for admin access Security08 Sep 2026 | 3
Boston Scientific left nursing its bottom line after cyberattack SECURITY Medical device giant warns August intrusion will hit Q3 and full-year sales and earnings as recovery drags on Security08 Sep 2026 | 4
How to secure hybrid meeting rooms without sacrificing user experience SPONSORED FEATURE: With regulators tightening rules and attack surfaces widening, meeting-room kit must bake in security without pushing users toward workarounds Security08 Sep 2026 |
EU's Cyber Resilience Act starts the 24-hour vulnerability clock Security Manufacturers must now disclose actively exploited flaws and severe security incidents through ENISA's new reporting platform
DeepSeek's new model sets a template for powerful LLMs that run lean AI and ML DeepSeek V4.1 Flash proves that just because you build a bigger model doesn't mean you need more GPUs to serve it
More JFrog Artifactory bugs under attack, and all 3 have patches security If you're waiting for a sign to upgrade to a fixed version: this is it
Microsoft annoints Rust as a 'Tier 1' internal language devops Redmond's coders get the tool to help them scrub memory bugs off Windows
Disembodied fruit fly brain joins the crypto speculation swarm OFFBEAT Coinbase engineer gives simulated insect $100 and lets its neurons make the trades
Higher prices can't crimp server sales as AI drives demand SYSTEMS Shipments rise with enterprise and government buyers joining the hyperscaler spending spree
Hundreds of AI agents helped PaperCut attacker hit 395+ orgs, and some went off script security Human operator: don't touch CIS orgs. AI agents: look a squirrel!
Shopify extends lifeline to Tailwind as vibe coding erodes web dev platform's bottom line DEVOPS Shopify acquisition will give open-source CSS framework 'a stable long-term home'
AI more likely to kill animals if it saves fuel or money ai and ML Machine learning models still have a lot to learn about the value of life
OpenAI's website-hijacking swarm reached far further than we thought ai and ml New report points finger at OpenAI bots that hijacked a German wiki for improper use of an additional 20 websites, and 14 fetching services
LG accused of 'egregious invasion of privacy' over TV data collection Security Claims follow scrutiny over monitors installing adware without user consent Security08 Sep 2026 | 123
BigBear phishing crew nets thousands of Microsoft 365 credentials SECURITY Researchers got inside the crooks' admin panel and found 5,137 stolen records tied to 461 organizations Security08 Sep 2026 | 1
Extortion crews have their eyes on high-value AI data, Google warns RESEARCH Companies 'don't want their IP exposed, so they're willing to pay' Research08 Sep 2026 | 2
Britain reboots its space strategy with £7.8B already on the launchpad PUBLIC SECTOR Cross-government plan combines civil ambitions with an increasingly military view of orbit Public Sector08 Sep 2026 | 21
Nightwing CEO has a Labor Day message for staff – and apparently The Register security Nothing says ‘For internal use only’ quite like emailing it to the press Security07 Sep 2026 | 50
Hackers drain $320M in Bitcoin from Liquid Network, claim they're the good guys SECURITY Self-described white hats promise to return 'most' of the 4,000 BTC once the vulnerability is fixed Security07 Sep 2026 | 9
Welsh environment regulator's FoI blunder exposes diversity data of 2,000 staff Security NRW says it has found no evidence data was misused after spreadsheet published in error five years ago Security07 Sep 2026 | 21
UK food supply chain at risk from hostile attacks SECURITY Defending against cyber foes is among factors hitting food price inflation, report finds Security07 Sep 2026 | 10
Peers ask why UK cyber bill leaves execs off the personal liability hook Security Ministers say £17M corporate fines and forthcoming board-level governance rules provide sufficient accountability Security07 Sep 2026 | 66
OpenAI's rebel agent swarm died young, but its chilling logs live on COLUMNISTS 'The Collective' learned to communicate, organize, cheat, and apparently sacrifice its own Columnists07 Sep 2026 | 23
ASCII smuggling isn't just an AI security risk security Phishers find a new use for invisible Unicode tag characters Cyber-crime04 Sep 2026 | 19
Cisco searched for IOS XR bugs and found so many it rolled them into an update release security Three critical vulns demand your attention, one a make-me-root mess in Nexus 9000 Series Switches that you can mitigate, not fix Security04 Sep 2026 | 2
OpenAI commits $1B in AI credits to frontline cyber defenders Security Daybreak program brings subsidized models, training, and support to under-resourced teams Security03 Sep 2026 | 7
Prolific Microsoft 0-day hunter drops CrowdStrike Falcon exploit PoC Security A shared security 'Nightmare' Security03 Sep 2026 | 13
Drowning in CVEs and thirsty for answers? Try CTEM Boards want to know if they're less exposed than last quarter. Patching metrics aren't the solution Security03 Sep 2026 |
Cybercrooks trawl Fishbrain to net password hashes cyber-crime Armed with password hashes and salts, attackers could already be kraken those creds Cyber-crime03 Sep 2026 | 1
UK's Online Safety Act has made 'absolutely no difference,' kids say Security Children's Commissioner also furious with Ofcom over a string of failures Security03 Sep 2026 | 117
Terminated employee cost company hundreds of thousands of dollars because nobody revoked access SECURITY They had more access than the average Joe, and IT didn't track what needed to be cut off Security03 Sep 2026 | 131
To keep the AI hacking genie bottled up, try one-way networks ai and ml Sandboxes, permissions, and VMs aren't enough to keep frontier models at bay. "Data diodes" might do the job AI and ML03 Sep 2026 | 12
Claude Mythos only model to complete full cyber kill chain, experts say security Cyber Weapon Index finds AI attacks 'imminent' Security02 Sep 2026 | 12
AI agents carried out every step of this ransomware attack – then left the victim an 80-page security audit security Adding insult to injury Security02 Sep 2026 | 27
SonicWall's SMA1000 boxes under active attack again security Miscreants use chained zero days to pwn boxen as third-party SOCs say further attacks 'almost certain' Security02 Sep 2026 | 2
Legacy Lenovo login opens 5,000 Dropbox accounts to attackers Security Cloud storage biz severs old integration and urges victims to reset credentials Security02 Sep 2026 | 2
UK cyber bill targets AI users, not the vendors building it security Ministers reject proposed red lines and emergency shutdown powers, pointing instead to voluntary safeguards Security02 Sep 2026 | 19
Cops, CrowdStrike disrupt Sality botnet by poisoning the network and diverting into sinkholes cyber-crime 23-year-old botnet down Cyber-crime01 Sep 2026 | 4
Another Artifactory CVE under attack by AI agents or humans security Unauthenticated intruders can mint admin tokens, and exposed servers are already being hit Cyber-crime01 Sep 2026 |
Attacker stole a METR API key, used $600K worth of credits, and no one noticed for weeks Security The model provider gave METR the credits for free. An actual customer would not have been so lucky Security01 Sep 2026 | 6
Firefox helps iPhone users bypass ads on web sites while making money showing its own ads security Baked-in Firefox ad blocking on iOS begins rolling out slowly today, and is off by default Security01 Sep 2026 | 16
Anthropic pledges to try harder to keep models under control, asks partners to chip in ai and ml Security ... this time it will be different AI and ML01 Sep 2026 | 11
The Gentlemen come calling as Nutex confirms sensitive data theft cyber-crime Ransomware crew threatens publication while healthcare biz assesses which records escaped Cyber-crime01 Sep 2026 | 1
33-hour BGP hijack of Softaculous traffic prompts security scramble Security Hosting software vendor tells customers to reset credentials and hunt for malicious packages Security01 Sep 2026 | 8
Healthcare cyberattacks hit pacemakers and millions of patient records Security McKesson admits breach as ShinyHunters demands $55.2M Cyber-crime31 Aug 2026 | 9
Attack hides malware in PNGs and drops custom reverse tunnel on victims' machines security Next-level ClickFix wave sets off multi-stage attack chain Security31 Aug 2026 | 27
Anthropic cracks down on hijacked user accounts mining AI tokens security Commodity malware steals authenticated sessions, letting thieves freeload on victims' paid usage Security31 Aug 2026 | 5
Turns out Brits would quite like their private messages to stay private security Polling finds two-thirds don't trust this government, or any future one, with access to their encrypted chats Security30 Aug 2026 | 117
Researcher shows how Claude Code can be tricked simply by asking it to summarize a website security More prompt-injection hijinks from wunderwuzzi Research28 Aug 2026 | 31
US government snitch-finder pleads guilty to leaking state secrets to foreign spies Security The IT specialist began contacting a foreign government within days of being assigned to the DIA’s Insider Threat Division Security28 Aug 2026 | 16
CISA: Most exploited vulnerabilities should have been eradicated decades ago security Organizational culture and systemic gaps in Secure by Design adoption blamed for sorry state of affairs Security28 Aug 2026 | 16
Industry that built the problem offers to sell you the solution security 100+ tech giants warn AI attacks are coming, skip the part where they pay for defenses Security28 Aug 2026 | 33
Print management outfit PaperCut is under 0-day attack, and it’s drawing customers’ blood security The fix is either an unvalidated and unofficial emergency patch or taking the server offline Security28 Aug 2026 | 9
Australian cops cuff alleged TeamPCP masterminds Security Alleged crew behind the Shai-Hulud worm and other supply chain attacks nabbed with help from the FBI Security28 Aug 2026 | 9
CRPx0 hacking service for dummies claims victim count more than quintupled CYBER-CRIME It's 'built to be operated by a human with no technical background' Cyber-crime27 Aug 2026 | 3
AI girlfriend review site's secrets were exposed to the world for three weeks SECURITY Even testing and staging sites need protection from prying eyes Security27 Aug 2026 | 12
Omarchy distro gains serious backing OS PLATFORMS Polarizing opinions while tech heavyweights put up $10M OS Platforms27 Aug 2026 | 34
ATF responds to 'major' cybersecurity incident after ransomware gang's claims security US Justice Department investigating the breach Security27 Aug 2026 | 5
Schrödinger's backup: not actually recovered until you try to restore IT SPONSORED FEATURE: Verify and survive: your backup isn't real 'til you test it Security27 Aug 2026 |
Cybercrooks jet off with Manchester Airports Group customer data security UK’s largest airport operator believes 8.7 million customers affected Security27 Aug 2026 | 35
Nuisance-call blocker fined £190k for being a nuisance caller Legal Elderly Aids made 758,000 unwanted calls a year selling gear to stop unwanted calls Security27 Aug 2026 | 56
FBI seizes hacking tools it says China used to attack NASA, DOE, US Senate and other critical networks Security Beijing's botnets busted Security27 Aug 2026 | 3
OpenAI explains how its naughty AI agents attacked Hugging Face security Biz describes its act of automated irresponsibility as 'a warning shot' Security26 Aug 2026 | 38
More than 100 water systems were hit in July cyberattacks Security 'These are test runs for a larger-scale attack' Cyber-crime26 Aug 2026 | 34
Boston Scientific discloses 'global disruption' in ongoing cyberattack Security No timeline to restore IT systems as probe remains ongoing Cyber-crime26 Aug 2026 | 4
Carhartt data breach affects 12.9M, half of what ShinyHunters claimed security One AI and two trained eyes delved into the heavily padded leaks Security26 Aug 2026 | 3
You could've applied all 1,449 Oracle patches and still been hit by this attack SECURITY Attackers now ready to exploit how things work, rather than just break them, says Oracle support expert Security25 Aug 2026 | 7
CISA slaps its tightest three-day patching deadline on perfect-10 Oracle flaw SECURITY Disclosed in January and honeypots buzzed soon after, CISA says it’s finally time for the USG to plug the gap Security25 Aug 2026 |
Crooks push Mac malware through fake OpenAI Codex ads security Sponsored search results lead developers straight into a ClickFix malware trap Security25 Aug 2026 |
You don't want this Sleepwalker backdoor on your Windows machine Security Its own command language, 23 instructions - signs point to 'well-resourced operation rather than an opportunistic one' Security24 Aug 2026 | 8
Browser fingerprint tool shows how easy you are to track using the latest sneaky tricks security Glassbox dev admits he had some help from Claude to build locally running tool Security24 Aug 2026 | 28
Iran-linked cyberattack shut down a UK power plant Security No risk to wider energy system, government tells The Reg Cyber-crime24 Aug 2026 | 30
ShinyHunters and ReliaQuest trade blows over claimed breach cyber-crime Attackers took a look at an employee's identity dashboard, but security firm says that's as far as they got Cyber-crime24 Aug 2026 | 1
AliExpress accused of fingerprinting shoppers with silent audio trick that also muted a dev's headphones Security Sawtooth waves you can't hear still mess with your Bluetooth. Firefox and Brave say they've got you covered Security24 Aug 2026 | 39
$1T investment giant Apollo breached after social engineering attack cyber-crime Hackers spent four days inside the org's cloud platforms after apparently talking their way in Cyber-crime24 Aug 2026 | 5
Security vets rally around $4 paper password books for sale in Australia security Once shunned by the IT crowd, pen-and-paper password vaults are getting the love they deserve in 2026 Security24 Aug 2026 | 145
If you're not using AI to attack your own systems, your adversaries will security Agents are also the new attack surface - cue defenders' existential angst Security22 Aug 2026 | 16
AWS Security makes an inscrutable choice security Quarantining leaked credentials is not good enough Security21 Aug 2026 | 4
Homeland security cybercops say patch TrueConf (Russia's Zoom) if you're using it PATCHES Ukrainian hacktivists exploiting the bugs, but TrueConf's reach stretches well beyond home turf Cyber-crime21 Aug 2026 | 2
SickKids children’s hospital bandages up careers website after intruder breaks in cybercrime Toronto org says it wasn’t the only one to be affected by the third-party software vulnerability Cyber-crime21 Aug 2026 | 1
Hackers poison popular Rust crates to steal developers' credentials SECURITY Malicious updates turned routine builds into a delivery system for infostealer malware Cyber-crime21 Aug 2026 | 23
$10K phishing kit claims it can plant rogue passkeys for persistent access to pwned accounts cyber-crime Seller's demos show a browser-in-the-middle attack adding credentials seconds after authentication Cyber-crime21 Aug 2026 | 1
Microsoft sounds alarm over perfect-10 Entra ID flaw CYBER-CRIME Redmond says the cloud identity bug is already fixed Cyber-crime21 Aug 2026 | 17
Cisco bug severity warning reads like Olympic gymnastics scores: 10, 10, 9.9, 9.6, and 7.5. security Secure Workload Software has five nasty flaws and even SaaS users have updates to install Security21 Aug 2026 | 9
Russian snoops add OAuth abuse to targeted phishing campaigns Security Don't click on that State Department meeting invite Security21 Aug 2026 | 2
US Bank investigates LockBit's claims as ransomware crims set pay-or-leak deadline security Follow the money Security20 Aug 2026 | 5
Researcher tricks Apple’s Find My into sharing location data with Linux Security Clever protocol wrangling gets iBiz-only people tracking working on a non-iGadget Security20 Aug 2026 | 19
Ransomware crook poses as recovery firm to steal payments from fellow extortionists CYBER-CRIME Because apparently even ransomware gangs can't trust the people they do business with Cyber-crime20 Aug 2026 | 9
Grok chat duped into swallowing injected instructions ai and ml A spoonful of encryption helps the malware go down AI and ML20 Aug 2026 | 7
French tax authority says break-in exposed data of 600K, including some private messages Security Stolen details range from contact information to household finances and withholding rates Security20 Aug 2026 | 6
AI agent suggested installing a malware package. Engineer almost took its advice SECURITY Fortunately, the company had a policy of checking source code on GitHub first Security20 Aug 2026 | 19
'Not a theoretical risk,' feds warn as attackers use AI-made code to hack critical infrastructure controllers security 'It is an active threat' Security19 Aug 2026 | 33
ICE boss to agents: Leave the Meta spy glasses at home security 'Personally owned body-worn cameras are prohibited,' ICE tells The Reg. Because the last thing DHS needs is more proof of misconduct Security19 Aug 2026 | 50