‘Budgets are moral documents,’ Rep. Delia Ramirez said This article has been indexed from www.theregister.com – Articles Read the original article: Dems slam Trump for making cybersecurity hold out the tin cup while splurging on ballroom and Jan. 6 ‘slush…
Category: www.theregister.com – Articles
Threat hunters find Google API keys still usable 23 minutes after deletion
Plenty of time for bad actors to grab data or hit you with a giant bill This article has been indexed from www.theregister.com – Articles Read the original article: Threat hunters find Google API keys still usable 23 minutes after…
HackerOne takes an axe to its bug bounty rewards
Critical flaw payouts slashed by more than 75% This article has been indexed from www.theregister.com – Articles Read the original article: HackerOne takes an axe to its bug bounty rewards
Attackers spill plaintext passwords of 46k Myspace93 users after 2021 breach
Leakage blamed on treacherous friends exposed unencrypted credentials, email addresses This article has been indexed from www.theregister.com – Articles Read the original article: Attackers spill plaintext passwords of 46k Myspace93 users after 2021 breach
Cisco serves up yet another perfect 10 bug with Secure Workload admin flaw
Switchzilla says attackers could access sensitive data and make configuration changes across tenant boundaries through vulnerable internal APIs This article has been indexed from www.theregister.com – Articles Read the original article: Cisco serves up yet another perfect 10 bug with…
Microsoft storms RAMPART, adds Clarity to agentic AI safety
Redmond open sources two tools for building and maintaining safer agents This article has been indexed from www.theregister.com – Articles Read the original article: Microsoft storms RAMPART, adds Clarity to agentic AI safety
Zombie user account let hackers control the city’s water
Failing to disable a former employee’s account was a huge mistake This article has been indexed from www.theregister.com – Articles Read the original article: Zombie user account let hackers control the city’s water
Even Claude agrees: hole in its sandbox was real and dangerous
Another day, another AI bug silently fixed with no CVE and no public disclosure This article has been indexed from www.theregister.com – Articles Read the original article: Even Claude agrees: hole in its sandbox was real and dangerous
GitHub says internal repos exfiltrated after poisoned VS Code extension attack
Initial assessment says customer data spared while users wonder what else may have slipped out This article has been indexed from www.theregister.com – Articles Read the original article: GitHub says internal repos exfiltrated after poisoned VS Code extension attack
London’s police asked Big Tech for comms data over 700,000 times last year
A Freedom of Information Act request shows the extent of the surveillance This article has been indexed from www.theregister.com – Articles Read the original article: London’s police asked Big Tech for comms data over 700,000 times last year
Microsoft shuts down illegal code-signing operation used by ransomware crims to mask their malware
‘Thousands’ of US victims, including 12+ machines owned and operated by Redmond This article has been indexed from www.theregister.com – Articles Read the original article: Microsoft shuts down illegal code-signing operation used by ransomware crims to mask their malware
America’s top cyber-defense agency left a GitHub repo open with with passwords, keys, tokens – and incredibly obvious filenames
I wonder what’s in ‘external-secret-repo-creds.yaml’ and ‘AWS-Workspace-Firefox-Passwords.csv’? This article has been indexed from www.theregister.com – Articles Read the original article: America’s top cyber-defense agency left a GitHub repo open with with passwords, keys, tokens – and incredibly obvious filenames
Clear your calendar, Drupal user: You have a critically urgent patch to install
The org’s staying mum on the details, but Wednesday’s fixes reach back to unsupported 8.9 branches This article has been indexed from www.theregister.com – Articles Read the original article: Clear your calendar, Drupal user: You have a critically urgent patch…
Do fear the Reaper – stealer swipes macOS users’ passwords, wallets, then backdoors them
While also spoofing all the trusted domains – Apple, Microsoft, and Google – in the same attack This article has been indexed from www.theregister.com – Articles Read the original article: Do fear the Reaper – stealer swipes macOS users’ passwords,…
Shai-Hulud copycat worm infects yet another npm package
Plus three other stealers in three other packages, all from the same scumbag This article has been indexed from www.theregister.com – Articles Read the original article: Shai-Hulud copycat worm infects yet another npm package
Linux kernel flaw opens root-only files to unprivileged users
Plus ModuleJail, a radical proposal for minimizing the impact of similar bugs This article has been indexed from www.theregister.com – Articles Read the original article: Linux kernel flaw opens root-only files to unprivileged users
TanStack weighs invitation-only pull requests after supply chain attack
Shai-Hulud worm exploited GitHub Actions misconfiguration to poison shared cache, now project weighing nuclear option on unsolicited contributions This article has been indexed from www.theregister.com – Articles Read the original article: TanStack weighs invitation-only pull requests after supply chain attack
NGINX Rift attackers waste no time targeting exposed servers
Researchers say 18-year-old flaw already being probed and exploited just days after disclosure This article has been indexed from www.theregister.com – Articles Read the original article: NGINX Rift attackers waste no time targeting exposed servers
Poland directs officials to ditch Signal in favor of ‘secure’ state-developed alternative
Shift comes amid mounting reports of successful social engineering attacks targeting higher-ups in government This article has been indexed from www.theregister.com – Articles Read the original article: Poland directs officials to ditch Signal in favor of ‘secure’ state-developed alternative
F-35 software delays leave UK buying time with US glide bombs
MoD says StormBreaker will plug gap until homegrown SPEAR 3 integration lands This article has been indexed from www.theregister.com – Articles Read the original article: F-35 software delays leave UK buying time with US glide bombs