CYBER-CRIME Massive password-stealing attack hits 75k Fortinet firewalls Why are you even reading this?! Rotate your passwords!!
Digital sovereignty needs an operating model PARTNER CONTENT Europe wants control over its own technology, but what does that look like?
Security Cisco adds another SD-WAN box to max-severity bug advisory Updated at the time? No sweat. Check those logs, though
DevOps Homebrew 6.0 released with new security mechanism, Linux sandbox and more Homebrew was "less vulnerable 10 years ago than npm is today," project lead tells us
Cyber-crime Helpdesk scammers are making house calls to make their lies feel more real 15-year-old among six arrested after Dutch cops target suspected bank fraud call center
CYBER-CRIME Cyberattack sees crops kept in the ground Bitter harvest for Australia's Mackay Sugar, attacked in peak cane crushing season
AI AND ML Python dev saved from disaster by intuition... and AI I'm sorry, Dave. I can't install that repo that will totally hose your system
Security Three critical Fortinet sandbox bugs splattered by unknown attackers All have patches, so make sure you upgrade to a fixed version
Cyber-crime Crooks found a new way to collaborate using Teams – by hiding command-and-control traffic Custom malware routed communications through legitimate Microsoft services, making malicious activity look like routine corporate collaboration
CYBER-CRIME Cardiac monitor maker's security skips a beat as data thieves go for the jugular Attackers used social engineering to access third-party business apps and steal patient information
PATCHES Cisco SD-WAN make-me-root bug under attack Second Catalyst SD-WAN Manager flaw exploited as an 0-day this month
security Feds freaked over Fable 5 after simple 'fix this code' prompt, not jailbreak, says researcher According to the one person who actually read the research paper
CYBER-CRIME Council of Europe hacked in ShinyHunters' PeopleSoft heist Joins the ranks of Nottingham Uni and 100 other unnamed victims
PUBLIC SECTOR Feds snooze as US datacenter law set to lapse with no replacement in site Federal Data Center Enhancement Act (FDCEA) of 2023 covers standards including security and sustainability
Security Microsoft site throwing warnings after someone forgot to renew cert Connectivity checker trips browser alarms thanks to lapsed security paperwork
RESEARCH PRC-linked spies hid inside medical and military networks for more than a year, snooping through Gmail and stealing data Google says the intruders were on the hunt for everything from drone tech to pathogens
Security Arch Linux locks down AUR signups amid wave of malicious commits Community repo freezes new accounts after attackers swamp it with poisoned package updates
AI AND ML AI is code – and can't be prompted into being smarter From Java tests to Shai-Hulud, bots keep proving they'll swallow anything you feed them
ai and ml NanoClaw now armed with JFrog for safer packages AI agents can't be trusted, so don't give them dangerous powers
Security Fired IT worker jailed for 21 months after sabotaging old school district Iowan’s scheme undone after misplacing trust in former coworker
Security Novo Nordisk reports cyberattack as UK gives Wegovy pill the nod Clinical trial participant data stolen, but pharma giant says exposed records were pseudonymized
SECURITY Microsoft has mostly repaired flaw in Surface hardware that allowed unprotected devices to be bricked by a single packet And it was Microsoft Copilot that unwittingly revealed the longstanding vulnerability
Security Google fires sueball at alleged Chinese phishers over AI-powered fraud ops Telegram-based 'Outsider Enterprise' accused of sending millions of scam texts and impersonating trusted brands
Security Plymouth council exposes hundreds in latest local government email gaffe Authority admits mass message to home-schooling families revealed recipients' addresses, prompting ICO report and apology
Public Sector UK digital ID gets brain trust to 'challenge' ministers on policy CEO of Mumsnet among the six-member team
Security ShinyHunters hacked 100+ orgs by exploiting an Oracle PeopleSoft 0-day University of Nottingham is first of many, Shiny tells The Reg
Security Microsoft's worst 'Nightmare' unleashes BitLocker bypass 0-day Another day, another Windows exploit code
security VRChat says somebody faked a breach notice with the Maine AG's office 'We have no reason to believe that our data or systems have been compromised. We are in the process of contacting the Maine Attorney General's office to have this removed.'
SECURITY Every employee’s password was stored in a single Excel file The CEO thought this was the best way to deal with some email issues
Security Chinese agents caught rebuilding botnets and stirring the pot on AI datacenter debate PRC eyes are watching you
Security Angry bug hunter with Microsoft beef drops new Windows 0-day Revenge is a dish best served code
DevOps GitHub pulls pin on npm's auto-run scripts Shai-Hulud worm exploited exactly this. Better late than never, says everyone except the malware authors
Patches Ivanti tells Sentry customers to patch now as critical bugs hit 10.0 and 9.9 Remote, unauthenticated RCE with root privileges is about as bad as it gets
PATCHES AI is making Patch Tuesday (kinda) fun again Unless you're an admin or vulnerability manager – then you're totally screwed
cyber-crime Miasma worms its way onto GitHub as attack kit goes open source As if there weren't enough package poisonings to worry about
personal tech Apple’s iOS 27 goes all agentic on compromised passwords, promises to change them with one tap iBiz might not win the AI race, but analysts say it's focusing on features people may actually use
SECURITY Signal says UK plan to scan devices for nude images 'endangers us all' Encrypted messaging app warns device-level checks could be repurposed for censorship
SECURITY Chrome's zero-day Whac-A-Mole continues with fifth exploited bug of the year Google paid researcher a tidy $55K bounty for its discovery
Security France probes compromise of gov messaging platform after account hijack Authorities say the breach only exposed public chat rooms, but alleged attacker claims to have accessed far more data
Cyber-crime Qilin NHS breach tally grows as Essex trust confirms stolen records Two years on from ransomware attack, hospitals are still trying to identify and warn patients
Security Norks blast 250+ fake job offers to developers over 6 weeks to try and snarf creds and crypto When an unsolicited job offer sounds too good to be true …
cyber-crime Ransomware crims got a month-long head start on Check Point VPN 0-day that now has a fix Scumbags, including a Qilin ransomware affiliate, began hitting this hole May 7
Cyber-crime Ransomware sends Illinois high school on an early summer vacation Meanwhile, 13 schools in Wales affected by separate attack
security GitHub nukes 70+ Microsoft repos, breaks CI/CD pipelines, following suspected worm infections Miasma worm shapeshifts, but cloud secret-scouting remains the goal
SECURITY NSO Group back in Meta's crosshairs after alleged WhatsApp targeting Zuckercorp says surveillance-for-hire vendor was still running phishing operations after federal court told it to knock it off
security Oxford Uni student data pwned yet again - this time via career platform breach Totally different attack from the break-in last month. Oh so that's OK then
cyber-crime If you don't fall for these extortionists' calls, they'll show up with USB sticks When 'Chatty Spider' morphs into tech services cosplay spider
security World Food Programme breach exposes data of 600k vulnerable Gazan families Those receiving aid in the famine-threatened, war-torn territory told support will remain
Security Council in UK's City of York outs hundreds of disabled residents with a single email blunder Blue Badge holders exposed to each other after BCC function proves too complex
CYBER-CRIME Pink is the latest goon squad to use fake helpdesk calls to steal creds A familiar tactic popularized by chaotic crime crew Lapsus$
Security OpenAI's agent chained decade-old DoS attacks to crash web servers in seconds Codex drops an HTTP/2 Bomb
Security Five Eyes: Watch out for odd LinkedIn connection requests, China's back on the hunt for state secrets Cash-for-intel tradecraft continues to concern intelligence officials years after it was first spotted
cyber-crime Duo who sold car crash victims' data must repay £118k Fresh penalties secured after initial prison, community service sentences for RAC double act
RESEARCH Nobody needs Mythos or 0-days to build a chaos-causing computer worm – free open source models work just fine 'Attackers can now cheaply operationalize known vulnerabilities at scale,' boffins tell The Reg
SECURITY All the passwords were stored in Active Directory description fields It was far too easy for a hacker to get the information
SECURITY Commvault says it's time to rethink resiliency as AI crooks leave victims in a 'dark, dead' state Those backup plans need backup testing
networks Bend the beam like Beckham to defeat anti-jamming tech It's hard to stop a signal jammer if you can't locate the source, say Rice University researchers
Security Another bug hunter leaks Microsoft exploits in defiance of company’s handling of vulnerability disclosures Researchers follow in Nightmare Eclipse’s footsteps, flipping off Redmond in favor of insta-leaks
Security UK banks offered access to OpenAI’s GPT-5.5 amid exclusion from Anthropic’s Glasswing expansion 150 new organizations inducted to cyber’s Soho House, including the first outside the US
cyber-crime 'Dumbass' criminal breaks the 'first rule of ransomware club' You don't infect anyone in Russia or other CIS countries
ai and ml Cisco sings Mythos' praises - but doesn't say how many bugs the model uncovered Meanwhile, Anthropic adds 150 partners to Project Glasswing
Security Russian spy agency says foreign spies turned officials' smartphones into surveillance devices FSB claims large-scale snoop op compromised phones of senior officials, but gives no technical evidence to back allegations
Security Microsoft reaches for olive branch after public dustup with 0-day researcher Following days of criticism from the security community, Redmond dials back rhetoric, insists vulnerability hunters not in its legal crosshairs
AI and ML Claude celebrates Anthropic's stock market float with blockbuster ... outage Chatbot has no respect for timing of its maker's financial announcement
Security Northern Ireland cops issue PSA after official phone number spoofed by scammers If you’re going to impersonate an officer, perhaps choose a more sophisticated way to nick cash than asking for gift cards…
Security Shai-Hulud malware worms Red Hat npm package versions downloaded 80K times a week TeamPCP? Or copycat malware dev?
Security Election interlopers register 5K+ domains, hope to catch some voting phish Hacking voting machines is so 2017. Phishing, impersonation pose the real election risks
Security GTA cheat service Atlas Menu hacked as attacker alleges screenshot spying A database containing 64,000 user records was published to GitHub after an attacker claimed to have compromised all Atlas systems
Cyber-crime Palo Alto VPN bug graduates from advisory to active exploitation Rapid7: Attackers exploit authentication bypass flaw in the wild, meaning more emergency patching for PAN-OS users
Security Password manager Dashlane suspends customer accounts amid brute-force attacks Engineers' weekends ruined as Dashlane's automatic protections kicked in
Networks Putin sends submarines to survey Britain's subsea cables. UK deploys Royal Navy, mobilizes parliamentary draftsmen Proposed legislation threatens fines and prison for reckless damage. Russian Prez must be shaking in his boots
Security Lone attacker published 14 malicious npm packages mimicking popular OpenSearch, Elasticsearch libraries And then Microsoft busted them all
public sector ICE to keep an eye on your eyes under $25M biometric scanner deal And you thought a face recognition app was intrusive?
Security No fix yet for critical RCE bug in open-source Git service Gogs - exploit module is out Researcher reported the vuln in March. Maintainers haven't responded to his messages since
Legal 23andMe inherits lawsuit over 'disturbing' DNA data breach California AG claims genetics biz downplayed 2023 mega-leak while paying ransom to attacker
Security Dutch cops wrest 17M devices from mystery botnet's clutches Hosting provider pulled the plug after police traced 200 servers to the Netherlands
Security ChatGPT blindly trusts browser content, turning the page into a payload You and me go ChatGPhish-ing in the dark
Research Russia-linked threat group put ChatGPT to work from lure to payload Researchers say 'GREYVIBE' crew used AI tools throughout a campaign targeting Ukrainian military and government
Cyber-Crime ShinyHunters adds Charter to trophy shelf after 4.9M customer records leak Telco giant says no sensitive data was taken, though names, addresses, phones, and emails are now out there
Security Troops’ phones gave away location data to foreign adversaries Lawmakers push DoD to tighten smartphone controls after adversaries exploited commercial tracking data
Security Disgruntled 0-day hunter 'humiliated' by Microsoft pledges 'bone shattering drop' as Redmond calls cops Six 0-days, three under active exploitation, more to come on July 14?
AI and ML Snowflake buys Natoma to help freeze out rogue agents It is the database titan’s sixth acquisition announcement since June 2025
os platforms Microsoft tests the 15-character limit of Windows Server admins' patience May security update trips over hostnames of a very specific length
Cyber-Crime Carnival confirms ShinyHunters cruised off with 6M customer records after April breach Travel and leisure giant was just one of many victims of the cybercrooks' crime spree this year
Security Company CEO flooded file share with smut, called for help after he deleted it Also, missing school iPad resurfaced after coach’s kids uploaded video to YouTube
cyber-crime CrowdStrike, Google shatter Glassworm botnet Developer-targeted, supply-chain attacks all the rage these days
AI + ML Bosses blinded by confidence about shadow AI use by workers More than half of orgs in Okta survey faced an AI-related security incident or near miss last year
Security Extortion crews are visiting law firms pretending to be tech support, FBI warns Cybercriminals still allowed to walk into office blocks and convince staff to let them plug in their own thumb drives
Security India's cyber agency sets clock at 12 hours to tackle exploited bugs as AI turns up the heat CERT-In says internet-facing or critical systems should be patched, mitigated, or cut off within half a day where feasible
Security How to guarantee a speaker gig: Hack the system. Literally Make your mark on the call-for-proposal platform
Security A Russian speaker and jailbroken Gemini went on a hacking spree and emptied at least one MAGA victim's crypto wallets
Security Dems slam Trump for making cybersecurity hold out the tin cup while splurging on ballroom and Jan. 6 'slush fund'
Security Microsoft shuts down illegal code-signing operation used by ransomware crims to mask their malware
Security America's top cyber-defense agency left a GitHub repo open with passwords, keys, tokens – and incredibly obvious filenames
Hardening open source projects may deter contributions TanStack weighs invitation-only pull requests after supply chain attack
Security Linus Torvalds says AI-powered bug hunters have made Linux security mailing list ‘almost entirely unmanageable’
Security Nobody believes the 'criminals and scumbags' who hacked Canvas really deleted stolen student data
patches Welcome to the vulnpocalypse, as vendors use AI to find bugs and patches multiply like rabbits
Columnists AWS to Quick admins: The access control didn't work, but you weren't using it anyway, so what's the problem?
Public Sector Vietnam to develop domestic cloud so it can ditch risky overseas operators for government workloads
cyber-crime Foxconn confirms cyberattack after ransomware crew claims it stole confidential Apple, Nvidia files
Cyber-crime First reports come in of victims of critical cPanel vuln as 'millions' of sites potentially exposed
Security OpenAI locks GPT-5.5-Cyber behind velvet rope despite slamming Anthropic for doing exactly that
Security Passport to £££: Home Office adds £216M to travel doc contract before a single bid's been placed
Cyber-crime Nearly half of UK businesses pwned last year as phishing keeps doing the job like it's 2005
Cyber-crime What type of 'C2 on a sleep cycle' do they leave behind? Novel Chinese spy group found in critical networks in Poland, Asia
Patches Microsoft's patch for a 0-day exploited by Russian spies fell short. Another Windows flaw is under attack
Security GitHub: Zounds, a genuinely helpful AI-assisted bug report that isn't total slop! Here, Wiz, take this wad of cash
Cyber-crime Burglar alarm biz burgled: ADT confirms cyber intrusion after ShinyHunters extortion attempt