Water system controllers don't belong on the internet, says ex-NSA chief after suspected Iran attacks Calling all defenders
Ransomware attacks spike as world distracted by AI What, you didn't think the top gangs were busy watching agents escape their sandboxes too, did you?
ShinyHunters called cancer diagnostics biz and tricked staffers into giving them access. Now they've dumped 10.9M email addresses Cancer diagnostics breach spills personal and health info as extortion crew says healthcare giant ‘should’ve paid the ransom’
Intrusion at US healthcare software provider puts 3.8M people's data at risk Unlimited Technology Systems says names, Social Security numbers, diagnoses, and insurance details may have been swiped
Snowflake extortionist admits 165-victim cloud crime spree – and squeezing one target twice Connor Moucka pleads guilty over sprawling 2024 campaign that looted billions of records
IBM's agentic AI platform is under active attack - patch now A critical Langflow flaw allowing RCE on default deployments is being exploited, says the CISA
Bypassing AI guardrails is so easy a script kiddie can do it Claiming 'it's my server' was often enough to persuade models to help
Police National Legal Database confirms data theft after dark web leak ExfilSquad claims 135,000 contact records weeks after hitting the Department for Education
AI is 'both the weapon and the target' in latest wave of cyberattacks CrowdStrike tracks 89% surge in machine-assisted activity as patch windows shrink to 48 hours
US bank places trust in ransomware crew that promised to delete its data History suggests this was not wise
Scotland's university procurement center confirms cybercrooks broke in APUC investigating after criminals claim historical data theft
Amazon links four poisoned npm packages to one North Korean crew Researchers say Sapphire Sleet socially engineered maintainers before publishing malicious updates through trusted accounts
Google goes it alone with a new cybercrime crew taxonomy So much for Microsoft and CrowdStrike’s plans for consistent names across the industry
Europol flags 4,340 'horrific' URLs linked to The Com Stop the spread (of online recruiting and propaganda)
Attackers pummel critical WordPress vuln to create all sorts of mischief Plus dozens of PoCs in the public domain
Scammers impersonate FBI on social media, prey on crime victims IC3 says any account claiming to represent it is fake
Frontier LLMs couldn't help Hugging Face fight off evil agents Chinese open-weight model GLM 5.2 happily obliged
Infosec expert: Paidwork users' data pwned after 23M-record database dumped online HIBP claims leaked info includes bank account numbers, payout histories, and personal details
Chinese President Xi Jinping wants emergency response systems to keep AI in check PLUS: Korean e-tailer Coupang's warehouse burns and burns; Australian Uni expels VMware; India's first private rocket flies first time; And more!
Ransomware curdles production at Coca-Cola's Fairlife dairy biz No use crying over spilled milk when US plants can't bottle it in the first place
C'mon, just copy this text string and paste it into your macOS Terminal – it'll fix your computer, honest Newly documented stealer ClickLock comes for the more trusting Mac user with spot of social engineering
Brit Scattered Spider duo handed tickets to prison over Transport for London attack Sentencing bookends the biggest cybercrime conviction in UK history
Tech support scam caused massive data breach at Australian airline Qantas It’s possible to leak PII describing 5.7 million people without breaching privacy rules
Cyberattack threatens utterly critical infrastructure in Japan: KFC The Colonel stops taking online orders and may close stores after logistics partner’s systems go down
German firm files for insolvency, blames cybercrims who shut down production for 6 weeks ZEGO-TVZ says the financial fallout from a March cyberattack left shutting its doors as the only option
An unnamed US county – perhaps in Ohio – paid $1M extortion demand to cybercriminals Leaked negotiations spill the tea
Accenture admits to 'isolated matter' after crook tries to flog alleged 35GB haul Consulting giant says it has 'remediated ... source' after crook claims to offer source code, keys, and cloud creds for sale
Suspected Chinese snoops caught breaking into universities' Roundcube mailservers Proofpoint researcher tells The Reg: 'We estimate the total volume of targets would be a few dozen'
Windows is watching: Anti-piracy tool fingers Scattered Spider suspect Along with other telemetry, Windows GDID makes online activity more traceable
CAI cloud worm gives competitors' malware the boot, then steals secrets and mines for coin Dog-eat-dog world for credential-stealing attackers
Predatorgate snoopfest victims launch €8M sueball at spyware maker Greek lawsuit comes as rights campaigners lobby the EU to take firmer stance on spyware abuses
Fake IT bods on Microsoft Teams coax workers into installing malware Unit 42 says attackers are posing as helpdesk staff and persuading employees to hand over remote control before dropping EtherRAT trojan
MFA-optional banks leave safe doors (and accounts) wide open for thieves to pillage Financial institutions are putting their clients at risk in the name of convenience.
Dev says Google warned him about account hijack – then charged him $11,000 anyway Left hand, meet right hand
Oracle E-Business Suite was under attack via critical flaw before the public exploit code was even released Attackers appear to have reverse-engineered Big Red's patch
EvilTokens device-code phishing kit totally more evil than we all thought It's a 'complete BEC operations environment,' Talos researcher says
Huntress CEO says threat hunter used 'poor judgment' in alerting ransomware crim about law enforcement probe Ex-employee claims this 'meets the definition of an insider threat'
Anonymous researcher drops 0-day 'exploitarium' repo At least two vulnerabilities are already under attack
Nissan says Oracle PeopleSoft break-in may have spilled payroll records, SSNs Carmaker points finger at an 'unknown' flaw as customer fallout continues
Amazon Q flaw let booby-trapped Git repos execute code, swipe cloud creds Researchers warn many AI coding assistants now execute commands from project configurations
Ex-Huntress analyst claims company insider fed info to a ransomware crim. Social media drama ensues Former employee accuses company of prioritizing pending IPO over client security
Microsoft uses AI to link two malware operations in racketeering suit 200+ C2 servers linked to StealC and Amadey shut down
You have got to be KDDI-ng – Japanese telco exposes 14.2 million managed email credentials Five ISPs and plenty of users await their fate
Security shops among the 'hundreds' of Klue hack victims As yet another extortion crew Icarus exploits Salesforce-linked integrations
Canadian utility fesses up to data breach, but key details remain off-grid London Hydro says names, addresses, account details may have been exposed, but much about the intrusion is unknown
Brazil probes emergency warning system after nationwide rogue alert Severe weather event alert platform buzzed devices across the country with the word 'misanthropy'
Cyber offenses now account for around a third of all crime across Asia and South Pacific Latest Interpol review shows how scams continue to dominate, and AI-enabled attackers prove too hot to handle for cash-strapped regions
Massive password-stealing attack hits 75k Fortinet firewalls Why are you even reading this?! Rotate your passwords!!
Cisco adds another SD-WAN box to max-severity bug advisory Updated at the time? No sweat. Check those logs, though
Helpdesk scammers are making house calls to make their lies feel more real 15-year-old among six arrested after Dutch cops target suspected bank fraud call center
Cyberattack sees crops kept in the ground Bitter harvest for Australia's Mackay Sugar, attacked in peak cane crushing season
Three critical Fortinet sandbox bugs splattered by unknown attackers All have patches, so make sure you upgrade to a fixed version
Crooks found a new way to collaborate using Teams – by hiding command-and-control traffic Custom malware routed communications through legitimate Microsoft services, making malicious activity look like routine corporate collaboration
Cardiac monitor maker's security skips a beat as data thieves go for the jugular Attackers used social engineering to access third-party business apps and steal patient information
Scammers keep scoring: Brits fleeced for £1.3B as Americans lose $3.5B to impersonators More reasons to love social media and AI
Council of Europe hacked in ShinyHunters' PeopleSoft heist Joins the ranks of Nottingham Uni and 100 other unnamed victims
ShinyHunters hacked 100+ orgs by exploiting an Oracle PeopleSoft 0-day University of Nottingham is first of many, Shiny tells The Reg
VRChat says somebody faked a breach notice with the Maine AG's office 'We have no reason to believe that our data or systems have been compromised. We are in the process of contacting the Maine Attorney General's office to have this removed.'
Malware scare keeps schoolkids home for a second day Great Marlow restricts network access while it investigates suspected infection
Nottingham Uni says student records raided after ShinyHunters claims cyberattack Crooks claim 40 GB haul as breach database pegs number of exposed email addresses at 455K
Miasma worms its way onto GitHub as attack kit goes open source As if there weren't enough package poisonings to worry about
Qilin NHS breach tally grows as Essex trust confirms stolen records Two years on from ransomware attack, hospitals are still trying to identify and warn patients
Ransomware crims got a month-long head start on Check Point VPN 0-day that now has a fix Scumbags, including a Qilin ransomware affiliate, began hitting this hole May 7
Ransomware sends Illinois high school on an early summer vacation Meanwhile, 13 schools in Wales affected by separate attack
If you don't fall for these extortionists' calls, they'll show up with USB sticks When 'Chatty Spider' morphs into tech services cosplay spider
Pink is the latest goon squad to use fake helpdesk calls to steal creds A familiar tactic popularized by chaotic crime crew Lapsus$
Duo who sold car crash victims' data must repay £118k Fresh penalties secured after initial prison, community service sentences for RAC double act
'Dumbass' criminal breaks the 'first rule of ransomware club' You don't infect anyone in Russia or other CIS countries
Election interlopers register 5K+ domains, hope to catch some voting phish Hacking voting machines is so 2017. Phishing, impersonation pose the real election risks
Palo Alto VPN bug graduates from advisory to active exploitation Rapid7: Attackers exploit authentication bypass flaw in the wild, meaning more emergency patching for PAN-OS users