When a one-line fix triggers thousands of PRs, something’s off A Go library maintainer has urged developers to turn off GitHub’s Dependabot, arguing that false positives from the dependency-scanning tool “reduce security by causing alert fatigue.”… This article has been…
Category: The Register – Security
UK data watchdog fines Reddit £14.47M for letting kids slip past the gate
Social media giant retorts it doesn’t want to collect ‘private’ data, and plans to appeal The UK’s data protection regulator has fined social media giant Reddit £14.47 million ($19.5 million) over its use of children’s data.… This article has been…
Korean cops charge teens over bike hire breach that exposed data on 4.62M riders
Public prosecutor mulls sentencing following investigations into two separate attacks Two South Korean teenagers were this week charged with breaching Seoul’s public bike service, Ttareungyi.… This article has been indexed from The Register – Security Read the original article: Korean…
UK tech hit by double trouble: Fewer foreign techies amid skills squeeze
Visa applications down, executives emigrating, and AI blamed for the rest The number of international workers applying for a visa to work in the UK’s tech sector dropped 11 percent between Q2 and Q3 2025, and was down 6 percent…
Euro allies aiming to rapidly build low-cost air defense weapons
We like our surface-to-air weapons affordable Britain has joined a handful of European allies in a program to develop low-cost air defense systems, including autonomous drones or missiles, with project delivery of the first elements scheduled for as early as…
Infosec community panics as Anthropic rolls out Claude code security checker
Not the first of its kind ai-pocalypse Anthropic sent the infosec community into a tizzy on Friday when it rolled out Claude Code Security, a new feature that scans codebases for vulnerabilities and suggests patches to fix the issues.… This…
Global regulators say AI image tools don’t get a free pass on privacy rules
Watchdogs warn models that can generate realistic images of people must comply with data protection laws A global coalition of privacy watchdogs has fired a warning shot at the generative AI industry, saying companies churning out realistic synthetic images can’t…
Break free of Ring’s servers, earn a five-figure bounty
Goal is to run software locally and stream only to owners’ computers If the sour taste has still not left your mouth after Ring’s Super Bowl ad, there is a $10,000 prize for anyone who can find a security flaw…
Suspected Anonymous members detained in Spain over post-flood DDoS blitz
Quartet accused of attacking public institutions, claiming the government was responsible for 2024 tragedy Spanish police say four self-proclaimed members of Anonymous are in custody after allegedly carrying out several cyberattacks on public authorities in the wake of the 2024…
AWS says more than 600 FortiGate firewalls hit in AI-augmented campaign
Off-the-shelf tools helped Russian-speaking cybercrime group run riot Cybercriminals armed with off-the-shelf generative AI tools compromised more than 600 internet-exposed FortiGate firewalls across 55 countries in just over a month, according to a new incident report from AWS.… This article…
Every day in every way, passwords are getting worse and worse
The only good password is no password at all Passwords turn 65 this year. They became a feature of computer users’ lives in 1961, with MIT’s Compatible Time-Sharing System (CTSS). Before then, sysops were real sysops. All jobs went through…
Attacker gets into France’s database listing all bank accounts, makes off with 1.2 million records
PLUS: Unpatched Ivanti boxes under attack; 0APT might not be a scam; AI gets better at helping cyber-scum; And more Infosec In Brief An unknown attacker accessed the French government’s database listing every bank account in the country and made…
UK council faces data breach claim after mishandling trans complaints
Confidential complainant details passed to local politician following debate A UK councillor has dubbed her local authority’s data breach “crazy” after the personal details of individuals behind a series of complaints were revealed to her.… This article has been indexed…
PayPal app code error leaked personal info and a ‘few’ unauthorized transactions
About 100 customers affected PayPal has notified about 100 customers that their personal information was exposed online during a code change gone awry, and in a few of these cases, people saw unauthorized transactions on their accounts.… This article has…
AI coding assistant Cline compromised to create more OpenClaw chaos
4K unintended installs in very odd supply chain attack Someone compromised open source AI coding assistant Cline CLI’s npm package earlier this week in an odd supply chain attack that secretly installed OpenClaw on developers’ machines without their knowledge. … This…
ShinyHunters demands $1.5M not to leak Vegas casino and resort chain data
What happens in Vegas… Las Vegas hotel and casino giant Wynn Resorts appears to be the latest victim of data-grabbing and extortion gang ShinyHunters.… This article has been indexed from The Register – Security Read the original article: ShinyHunters demands…
Ukrainian gets five years for helping North Koreans secure US tech jobs
Polish arrest leads to extradition and federal prison sentence Ukrainian national Oleksandr Didenko will spend the next five years behind bars in the US for his involvement in helping North Korean IT workers secure fraudulent employment.… This article has been…
Founder ditches AWS for Euro stack, finds sovereignty isn’t plug-and-play
Attempt to go ‘Made in EU’ offers big tech escapees a reality check where lower cloud bills come with higher effort Building a startup entirely on European infrastructure sounds like a nice sovereignty flex right up until you actually try…
CISA gives federal agencies three days to patch actively exploited Dell bug
Hardcoded credential flaw in RecoverPoint already abused in espionage campaign Uncle Sam’s cyber defenders have given federal agencies just three days to patch a maximum-severity Dell bug that’s been under active exploitation since at least mid-2024.… This article has been…
Ex-Google engineers accused of helping themselves to chip security secrets
Feds say trio conspired to siphon processor and cryptography IP, allegedly routing some data overseas Two former Google engineers and a third alleged accomplice are facing federal charges after prosecutors accused them of swiping sensitive chip and security technology secrets…