///
See Also: Shopee Pay | Shutterstock

Headlines : Theregister Sec News   Page 1    



AI recruiting biz Mercor says it was 'one of thousands' hit in LiteLLM .. - 2/04 8:02 am

First public downstream victim, but won't be the last AI hiring startup Mercor confirmed it was "one of thousands of companies" affected by the LiteLLM supply-chain attack as the fallout from the Trivy compromise continues to spread.





Amazon security boss: AI makes pentesting 40% more efficient - 2/04 4:00 am

Plus: how to train your human AI interview Amazon has seen a 40 percent efficiency gain by using AI tools to pentest its products before and after launch, according to security chief CJ Moses.





'People's Panel' to check if UK wants controversial Digital ID will cost .. - 1/04 10:23 pm

We could tell you no for free The UK government will spend about 630,000 running a discussion panel on its digital identity card plans, which minister James Frith said will "consider different perspectives and debate trade-offs" alongside a formal consultation .





UK manufacturers under cyber fire with 80% reporting attacks - 1/04 4:30 pm

ESET says factory outages, lost revenue, and supply chain disruption are becoming routine Nearly 80 percent of British manufacturers say they've been hit by a cyber incident in the past year, as new research suggests disruption on the factory floor is no longer an exception but business as usual.





Don't open that WhatsApp message, Microsoft warns - 1/04 5:18 am

How to avoid social engineering attacks? Employee training tops the list Be careful what you click on. Miscreants are abusing WhatsApp messages in a multi-stage attack that delivers malicious Microsoft Installer (MSI) packages, allowing criminals to control victims' machines and access all of their data.





Iran targets M365 accounts with password-spraying attacks - 1/04 3:09 am

Researchers say some targets correlate with cities hit by Iranian missile strikes Suspected Iran-linked threat actors are conducting password-spraying attacks against hundreds of organizations, primarily Middle Eastern municipalities, in campaigns that security researchers believe may have been aimed at supporting bomb-damage assessment following missile strikes.





Supply chain blast: Top npm package backdoored to drop dirty RAT on dev .. - 1/04 2:46 am

Hijacked maintainer account let attackers slip cross-platform trojan into 100M-downloads-a-week Axios One of npm's most widely used HTTP client libraries briefly became a malware delivery vehicle after attackers hijacked a maintainer's account and slipped a remote-access trojan (RAT) into two seemingly legitimate axios releases, in what's being described as "one of the most impactful npm supply chain attacks on record."





OpenAI patches ChatGPT flaw that smuggled data over DNS - 31/03 3:36 am

Check Point says outbound controls blocked web traffic but overlooked DNS OpenAI talks up data security for its AI services, yet Check Point says that ChatGPT allowed data to leak through a DNS side channel before the flaw was fixed.





Telnyx joins LiteLLM in latest PyPI package poisoning tied to Trivy breach - 31/03 1:42 am

Also, EU probes Snapchat, RedLine suspect extradited, AstraZeneca leak claim surfac





Citrix NetScaler bug exploited in days, may be multiple flaws in a trench .. - 30/03 9:49 pm

Researchers say attackers are already looting vulnerable boxes In-the-wild exploitation of a critical Citrix NetScaler bug has begun less than a week after disclosure, with researchers warning that attackers are already poking and pillaging vulnerable boxes.





European Commission admits attackers broke into public web systems, but .. - 30/03 6:15 pm

Brussels notifying 'Union entities' whose data may've been snatched in websites breach The European Commission has admitted that attackers broke into its public-facing web infrastructure and siphoned off data in a bare-bones disclosure that answers the what but ducks most of the how.





Security contractor blew the whistle on support crew's viral indifference - 30/03 3:30 pm

Career-limiting stupidity and rudeness exposed, with terminal consequences Who, Me? The week before Easter may be a short one for many in the Reg -reading world, but that won't stop us from opening it with a fresh installment of Who, Me? It's the reader-contributed column in which you share stories of things you did at work that had interesting consequences.





US foreign router ban criticized for being industrial policy disguised as .. - 30/03 12:49 am

Public policy professor says it will make America less secure but hits Netgears lobbying goals The United States ban on foreign-made SOHO routers wont improve security, and only makes sense as industrial policy disguised as cybersecurity, according to Milton Mueller, Professor at the University of Georgias School of Public Policy and founder of its Internet Governance Project.





Iran war drives urgent needto counter underwater attack drones - 27/03 11:43 pm

US and UK forces seeking tech tender with an April 3 deadline The UK and US are looking for technology to counter the threat posed by underwater drones to ships, harbors and other critical maritime infrastructure, and are asking industry for answers.





AFC Ajax drops ball as flaws let hackers play admin with tickets and bans - 27/03 8:30 pm

Vulns in Dutch football club's systems didn't just expose data they let outsiders play with accounts, and even lift stadium bans Dutch football giant AFC Ajax has admitted to a data breach after an attacker gained access to its internal systems, in an incident that looks less like a stray p





Security boffins scoured the web and found hundreds of valid API keys - 27/03 3:04 pm

Global bank's devs have some cleaning up to do after cloud creds found in website code Computer security boffins have conducted an analysis of 10 million websites and found almost 2,000 API credentials strewn across 10,000 webpages.





Brit lawmaker targeted by AI deepfake fails to get answers from US Big Tech - 26/03 7:49 pm

Appearing before Parliament, Meta, Google and X struggle to explain how fake political video circulated for so long A member of the UK Parliament's lower house who was the victim of a deepfake AI campaign this week had a rare chance to confront the Big Tech executives who helped spread it. Their answers disappointed.





UK wants to know if banning under-16s from social media does anything .. - 26/03 5:30 pm

300 families undergo 6-week trial to test impact on sleep, school, and home life The UK government will trial different levels of restrictions on social media for under-16s with the help of 300 families, alongside a public consultation that has already gathered nearly 30,000 responses.





Indian government probes CCTV espionage operation linked to Pakistan - 26/03 11:18 am

Police found cameras pointing at infrastructure Indian authorities have reportedly ordered an audit of the nations CCTV cameras, after police uncovered what they claim was a Pakistan-backed surveillance operation.





AI supply chain attacks dont even require malwarejust post poisoned .. - 26/03 4:52 am

A proof-of-concept attack on Context Hub suggests there's not much content santization A new service that helps coding agents stay up to date on their API calls could be dialing in a massive supply chain vulnerability.





Scammers have virtual smartphones on speed dial for fraud - 26/03 4:25 am

They cleverly mimic most traits of a real phone Smartphones have fast become the basis of our digital identities, securing payment systems and bank accounts. Now virtual devices that pretend to be real handsets have become a key tool for financial scammers, according to one company.





Jen Easterly, cybersecurity's 'relentless optimist,' hopes feds come back .. - 26/03 3:39 am

Ex-CISA boss also says no reason to panic about AI and security RSAC 2026 "Everybody feels massive FOMO if they don't get to RSAC," Jen Easterly says.





Only Trump can decide when cyberwar turns into real war - 26/03 2:55 am

Four former NSA bosses walk onto the stage at RSAC rsac 2026 There's a theoretical red line with cyber warfare. Cross it, and the US will respond with a physical attack like missile strikes. And that line "is whatever the President says it is," according to former NSA boss retired General Paul Nakasone.





Enterprise PCs are unreliable, unpatched, and unloved compared to Macs - 25/03 3:29 pm

Omnissa telemetry suggests business buyers are loving Apple and Google End- user compute vendor Omnissa, the company formed by the spin-out of VMwares virtual desktops, applications, and device management biz, has dug into the telemetry it collects from customers and painted a picture of the worlds enterprise hardware fleet and the news is better for Google and Apple than it is for Microsoft.





EFF has a new boss to lead the fight against privacy-sucking forces of doom - 25/03 6:44 am

Cyber rights org retools for the days of AI and unrestrained government interview The Electronic Frontier Foundation (EFF) on Tuesday appointed Nicole Ozer to succeed Cindy Cohn as the cyber rights group's executive director when Cohn departs this summer.





1K+ cloud environments infected following Trivy supply chain attack - 25/03 4:31 am

Crims 'creating a snowball effect' across open source projects RSAC 2026 Thousands of organizations' cloud environments have been infected with secret- stealing malware as a result of the Trivy supply-chain attack last week, and now the crims that compromised the open source scanners are working with notorious extortion crews like Lapsus$.





LiteLLM loses game of Trivy pursuit, gets compromised - 25/03 3:11 am

Python interface for LLMs infected with malware via polluted CI/CD pipeline Two versions of LiteLLM, an open source interface for accessing multiple large language models, have been removed from the Python Package Index (PyPI) following a supply chain attack that injected them with malicious credential- stealing code.





Country that put backdoors into Cisco routers to spy on world bans foreign .. - 24/03 9:48 pm

Unfortunately, there aren't many options unless you're Starlink Citing national security fears, America is effectively banning any new consumer-grade network routers made abroad.





HackerOne slams supplier for delayed breach notice after staff data exposed - 24/03 9:27 pm

Nearly 300 employees caught up in intrusion at benefits provider Navia Almost 300 HackerOne employees are caught up in a data breach, with the bug bounty biz slamming a third-party benefits provider for a weeks-long delay in notification.





Russian initial access broker who fed ransomware crews gets 81 months in .. - 24/03 7:32 pm

Aleksei Volkov sentenced after enabling attacks that cost victims millions A Russian national who sold the keys to corporate networks faces nearly seven years in a US prison after prosecutors tied his handiwork to a string of ransomware attacks costing victims millions of dollars.





Claude attacks were 'Rorschach test' for infosec community, scaring former .. - 24/03 6:50 am

'It freakin' worked' says Rob Joyce - and shows how relentless AI agents can find holes humans miss RSAC 2026 The now-infamous Anthropic report about Chinese cyberspies abusing Claude AI to automate cyberattacks was a Rorschach test for the infosec community, according to former NSA cyber boss Rob Joyce.





Public-private partnerships vital in disrupting China's Typhoons, says RSA .. - 24/03 6:46 am

Washington content to be represented by actual empty chairs RSAC 2026 Back in the day (circa 2023) when cybercrime group Scattered Spider and its help-desk voice-phishing calls were a relatively new threat, the feds considered pulling the government's top cyber-threat hunters and their private-sector counterparts into one room to share information, in real time, about this loosely knit extortion ring that was terrorizing enterprises.





Smooth criminals talking their way into cloud environments, Google says - 24/03 6:45 am

Voice phishing is second most common initial access method across all IR probes, and top in cloud break-ins RSAC 2026 Voice phishing surged last year to become the second most common method used by cybercriminals to gain initial access to their victims' IT estate and the No. 1 tactic used when breaking into cloud environments.





Lightning-fast exploits make it essential to patch fast, ask questions .. - 24/03 4:42 am

Here's where you ought to spend your security billable hours budget this year Strengthen your MFA policies, double-down on anti-phishing training, and for Jobs' sake, patch all your vulns right away. The past year of intelligence collected by Cisco's Talos threat hunters suggests that attackers are moving faster to exploit vulns, and fooling more staff than ever into giving up their credentials.





US chip testing firm shrugged off ransomware hit as minor then came the .. - 24/03 12:47 am

Trio-Tech International initially said hack wasn't 'material,' but then stolen data was published Trio-Tech International initially shrugged off a ransomware attack at a Singapore subsidiary as immaterial, only to reverse course days later after discovering stolen data had been disclosed.





Google unleashes Gemini AI agents on the dark web - 23/03 11:05 pm

Claims it can analyze millions of daily events with 98 percent accuracy Google's Gemini AI agents are crawling the dark web, sifting through upward of 10 million posts a day to find a handful of threats relevant to a particular organization.





RSAC 2026: Uncle Sam backs out, and AI agents are everywhere - 23/03 8:24 pm

Infosec pros descend on San Francisco kettle When El Reg cybersecurity editor Jessica Lyons joins infosec industry colleagues in San Francisco for RSAC 2026 this week, she's expecting agentic AI to be on everyone's lips - at least those who aren't busy gossiping about the lack of presence from any representatives of the US federal government.





Microsoft fixes broken Windows update days after vowing fewer broken .. - 23/03 7:24 pm

The era of reliability begins... right after this out-of-band patch Microsoft has released an out-of-band update to resolve bugs introduced by a Windows patch just days after promising improved reliability.





The drone swarm is coming, and NATO air defenses are too expensive to cope - 23/03 6:14 pm

Ukraine's battlefield lessons show quantity and affordability now trump exquisite hardware NATO is unprepared to deal with attacks by cheap, mass- produced drones and urgently needs layered, affordable air defense systems to counter the threat, taking a cue from the experience gained by Ukrainian forces over the past four years.





Russians are posing as Signal support to launch phishing attacks - 23/03 7:22 am

PLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more! Infosec In Brief Russian intelligence- affiliated parties are posing as customer support services on commercial messaging applications such as Signal to compromise accounts and conduct phishing attacks, the FBI and Cybersecurity and Infrastructure Security Agency (CISA) warned last Friday.




Reformasi     >>



Diplomatik PMX mula membuahkan hasil - Harapandaily
Seorang wakil rakyat kerajaan menggesa orang ramai supaya terus meletakkan kepercayaan terhadap kepimpinan negara dalam menghadapi ketidaktentuan global susulan ketegangan di Asia Barat. ADUN Batu Uban, A. Kumaresan berkata, pendekatan diplomasi Perdana Menteri, Datuk Seri Anwar Ibrahim, kini mula menunjukkan ..
Kroni     >>



Rafizi sedang rasai apa yang dibuat kepada arwah .. - Utusan
KUALA LUMPUR: Bekas setiausaha politik kepada Allahyarham Tan Sri Khalid Ibrahim menyifatkan, Datuk Seri Rafizi Ramli berkemungkinan sedang mendapat kifarah terhadap apa yang beliau lakukan selaku arkitek yang merangka strategi Langkah Kajang lebih 10 tahun lalu. Faekah Husin berkata, walaupun ..
Tabloid     >>



Papa Doakan Apa Adik Bisik Dimakbulkan Norman Hakim .. - Siraplimau
Perkongsian terbaharu pelakon Norman Hakim kembali mencuri perhatian ramai apabila dia memuat naik video penuh emosi di Instagram yang memaparkan momen bersama anak perempuannya, Marissa Dania. Video tersebut dimuat naik sekitar 10 jam lalu dan disertakan dengan kapsyen doa yang menyentuh hati ..
Tech     >>



Samsung Galaxy A27 runs Geekbench with a surprising .. - Gsmarena
Samsung unveiled the Galaxy A37 and Galaxy A57 in late March, and the Galaxy A27 should have joined them according to a rumor from November. Alas, it didn't, but it's definitely still in development. In fact, a prototype has now been spotted in the Geekbench online database. As you can see, it ..
World     >>



Trump mulls Nato withdrawal, stopping weapons to .. - Middleeasteye
Trump mulls Nato withdrawal, stopping weapons to Ukraine over Europe's response to Iran war Submitted by MEE staff on Wed, 04/01/2026 - 19:33 US president threatens to quit decades-old European alliance, as he fails to address Iran's control of Strait of Hormuz US President Donald Trump, right, ..
Motor Trend     >>



Toyota Urban Cruiser EV Dipratonton Di Malaysia, Harga .. - Piston
Antara trio kenderaan elektrik (EV) yang dipratontonkan hari ini di Malaysia oleh UMW Toyota adalah Toyota Urban Cruiser EV, yang bakal bersaing dengan beberapa model SUV kompak EV sedia ada di pasaran tempatan dengan harga bermula dari RM 198,000. Urban Cruiser merupakan ..