Pope's official prayer app commits cardinal sin, leaks 700K+ users' info (Security) hole-ier than thou
Europol flags 4,340 'horrific' URLs linked to The Com Stop the spread (of online recruiting and propaganda)
Uncle Sam tells overseas cybercrooks their visas are canceled Policy targets online scammers, sextortionists, and potentially their immediate families
OpenAI-Hugging Face attack doesn't mean agents are evil – unless you tell them to be Attack models gonna attack
Researchers replace downloaded macOS apps with evil twins, Apple shrugs Gatekeeper has one job and it's not doing it for some software
Millions of California-bought cars can be hijacked via Bluetooth Aftermarket dealer-installed KARR/SWDS security systems all use the same secure key, say UCSD researchers
Oracle drops 1,449 security patches like it's the new normal Experts say the era of AI bug hunting is here, so defenders will simply have to adapt to busier workloads
Iran-linked crews are probing more flavors of US industrial kit CISA widens alert beyond Rockwell controllers as intruders target internet-facing devices across critical infrastructure
One ChatGPT link could smuggle a rogue AI agent into your company Researchers say OpenAI flaw let phishing bait create an autonomous corporate mole armed with employee access
Swiss train maker tells ransomware crooks to get off at the next stop Stadler refuses $12.3M demand after thieves swipe technical data through supplier platform
Talking smack about a doctor got him access to private medical files Who needs a working security badge when you know how to talk your way into the records room?
OpenAI scored an own goal with Hugging Face attack, showing how open Chinese models are winning Closed models with guardrails can still cause harm, but may also not be able to fix problems they caused
Linux kernel team publishes 432 CVEs in two days Sunday-to-Monday onslaught fuels speculation over AI-assisted bug reports
Sneaky Windows stealer targets 300+ apps, gives crims an AI profiler to maximize profits Move over Flipper. There's a new Dophin X in town
Greedy ransomware crews return for seconds after victims cough up first extortion payments Some never saw their files again either, infosec biz Proofpoint finds
Council worker spared prison after four-day data-snooping spree Herefordshire employee handed suspended sentence for breach of Computer Misuse Act
OpenAI admits it was the source of the agent swarm that attacked Hugging Face Sandboxed experiment found itself a zero day, escaped onto the open internet and validated scary predictions about rogue agents
Kratos phishing-as-a-service kit loses its battle with international law enforcement Alleged developer arrested in Indonesia after more than 200 servers slain
AI music platform Suno hits bum note as 55M users exposed in data breach, claims infosec expert Have I Been Pwned confirms scale for first time
Intel fortifies Foundry with an actual customer: Fortinet Firewall maker looks to safeguard its custom ASIC production with homegrown silicon
OVH reveals semi-secret plan to fix critical Januscape hypervisor bug with mass reboots – and an Australian crash-test dummy French cloud backported a patch into Debian and didn’t seek customer consent, despite chance of downtime
Attackers pummel critical WordPress vuln to create all sorts of mischief Plus dozens of PoCs in the public domain
Scammers impersonate FBI on social media, prey on crime victims IC3 says any account claiming to represent it is fake
Malicious cloud customers can bring down the power grid Datacenters tax utilities normally, so just imagine what they could do if workloads were designed to destroy
Frontier LLMs couldn't help Hugging Face fight off evil agents Chinese open-weight model GLM 5.2 happily obliged
Microsoft 365 calendars become spy drop boxes in HOLLOWGRAPH campaign Malware hides commands in appointments set for 2050 and uses Redmond's own cloud to phone home
Infosec expert: Paidwork users' data pwned after 23M-record database dumped online HIBP claims leaked info includes bank account numbers, payout histories, and personal details
Chinese President Xi Jinping wants emergency response systems to keep AI in check PLUS: Korean e-tailer Coupang's warehouse burns and burns; Australian Uni expels VMware; India's first private rocket flies first time; And more!
Connecting AI agents to outside services explodes the risk radius Connect all the things and watch what happens
AI spam filters are getting suckered by old-school text salting Turns out decades-old email tricks still work against some LLM-powered email filters
Attackers target critical FortiSandbox flaws as CISA issues patch order Command injection vulns land on exploited list after researchers spot abuse attempts
Ransomware curdles production at Coca-Cola's Fairlife dairy biz No use crying over spilled milk when US plants can't bottle it in the first place
Google fixing Android lock screen bug that lets Gemini send SMS without a PIN A specific multi-touch gesture bypasses an authentication prompt, allowing anyone to send messages
South Korea making its own security-centric AI model Adapting existing local LLM project for security and sovereignty purposes and hopes to one day match Mythos
OpenAI admits GPT-5.6 occasionally deletes files – but it's an 'honest mistake' Data purges deemed an example of 'misaligned behavior' that upstart is working to avoid
Researcher poisons open-weight AI model for under $100 Models demand trust without offering verification
C'mon, just copy this text string and paste it into your macOS Terminal – it'll fix your computer, honest Newly documented stealer ClickLock comes for the more trusting Mac user with spot of social engineering
Brit Scattered Spider duo handed tickets to prison over Transport for London attack Sentencing bookends the biggest cybercrime conviction in UK history
Windows 10 refuses to die, and the security bill is coming due One in six machines still run the old OS as migration stalls and patch deadlines creep closer
Telegram shortlinks knocked offline over sanctioned VPN connection t.me borked for a day until platform proved it had no ties to service favored by cybercriminals
Law firm insisted on one password to rule them all Using the admin password, you could be anyone and see anything
Tech support scam caused massive data breach at Australian airline Qantas It’s possible to leak PII describing 5.7 million people without breaching privacy rules
Cyberattack threatens utterly critical infrastructure in Japan: KFC The Colonel stops taking online orders and may close stores after logistics partner’s systems go down
CISA sounds alarm over trio of exploited SharePoint flaws Three bugs are under active attack, and two more critical holes could add to the pain
Microsoft cancels Patch Tuesday for some Dell users over surprise shutdowns, overheating devices Mega hardware vendor reports problems - but Windows maker isn't yet naming affected models
LegacyHive: 'Bone-shattering' zero-day from Microsoft's serial tormentor not the haymaker that was promised Experts say it’s a useful post-compromise tool, for those with the brain cells required to put it together
Patchpocalypse Now: Microsoft tops last month's record with 622 Patch Tuesday CVEs Remember when last month's 206 CVEs seemed eye-watering? Yeah, those were the days
Welsh Doxbin admin jailed for egging on swatters from behind a screen Callum Dare encouraged others to carry out dangerous hoaxes, made mini-movies from the footage
Musk promises purge after Grok Build caught sending entire repos to the cloud Researcher confirms the uploads have stopped, but says xAI's privacy command was not what fixed them
'The bots are alive!' Jailbroken Gemini spun up new C2 server for Russian fraudster in just 6 minutes Human did 10% of the job, AI did 90%
Baddies caught exploiting extensions bugs with perfect 10 scores on vulnerable Joomla websites Flaws in iCagenda, Balbooa Forms extensions can impact open source CMS that powers a million sites worldwide
German firm files for insolvency, blames cybercrims who shut down production for 6 weeks ZEGO-TVZ says the financial fallout from a March cyberattack left shutting its doors as the only option
EU and UK officially blame Russian spies for cyberattack on Poland's power grid Sweeping sanctions and condemnation follow op that could have left half a million without power in the depths of winter
World Cup grudge attackers may have scored Argentine FA access via year-old infostealer infection Footie fans? Overreacting? There's a first time for everything
Progress orders emergency ShareFile server shutdown over mystery security threat Vendor insists there's no evidence of unauthorized access, but it's asking customers to take one of the most drastic precautions available
Destructive Windows backdoor stuffs multiple wipers and ransomware code into a single package Microsoft says GigaWiper combines at least 3 malware families into one modular tool
Fashion mart Miinto unzips breach details, warns shoppers to watch for phisherfolk Copenhagen company ‘sorry’ after 'perpetrator' pops order management system
Scot NHS Trust probes email stuffup involving maternity patients' data NHS Forth Valley is the latest health board to bungle basic email data protection principles
Microsoft warns customers AI will mean busier Patch Tuesdays More patches mean more reasons to buy Redmond’s auto-patching tools
An unnamed US county – perhaps in Ohio – paid $1M extortion demand to cybercriminals Leaked negotiations spill the tea
EU 'Chat Control' snoopfest returns after vote to kill it falls short Opponents won the count but missed the 360-seat threshold needed to stop the interim CSAM-scanning rule
Microsoft closes book on Nightmare Eclipse's RoguePlanet zero-day Weeks after the exploit code dropped, Redmond has finally ships a fix for the Defender zero-day
Accenture admits to 'isolated matter' after crook tries to flog alleged 35GB haul Consulting giant says it has 'remediated ... source' after crook claims to offer source code, keys, and cloud creds for sale
Thief posed as Wi-Fi fixing hero, then stole priceless trophy If people think you are doing a legitimate job, you can get away with anything
Suspected Chinese snoops caught breaking into universities' Roundcube mailservers Proofpoint researcher tells The Reg: 'We estimate the total volume of targets would be a few dozen'
GitHub Copilot: Sorry Dave, I can't do that harmful thing - unless you ask me in code More fun with AI jailbreaks, this time at the workflow level
Tool promises to make lazy academics' AI-written papers sound more human Startup insists it's not trying to help anyone cheat the system - honest!