The org’s staying mum on the details, but Wednesday’s fixes reach back to unsupported 8.9 branches This article has been indexed from www.theregister.com – Articles Read the original article: Clear your calendar, Drupal user: You have a critically urgent patch…
Category: www.theregister.com – Articles
Do fear the Reaper – stealer swipes macOS users’ passwords, wallets, then backdoors them
While also spoofing all the trusted domains – Apple, Microsoft, and Google – in the same attack This article has been indexed from www.theregister.com – Articles Read the original article: Do fear the Reaper – stealer swipes macOS users’ passwords,…
Shai-Hulud copycat worm infects yet another npm package
Plus three other stealers in three other packages, all from the same scumbag This article has been indexed from www.theregister.com – Articles Read the original article: Shai-Hulud copycat worm infects yet another npm package
Linux kernel flaw opens root-only files to unprivileged users
Plus ModuleJail, a radical proposal for minimizing the impact of similar bugs This article has been indexed from www.theregister.com – Articles Read the original article: Linux kernel flaw opens root-only files to unprivileged users
TanStack weighs invitation-only pull requests after supply chain attack
Shai-Hulud worm exploited GitHub Actions misconfiguration to poison shared cache, now project weighing nuclear option on unsolicited contributions This article has been indexed from www.theregister.com – Articles Read the original article: TanStack weighs invitation-only pull requests after supply chain attack
NGINX Rift attackers waste no time targeting exposed servers
Researchers say 18-year-old flaw already being probed and exploited just days after disclosure This article has been indexed from www.theregister.com – Articles Read the original article: NGINX Rift attackers waste no time targeting exposed servers
Poland directs officials to ditch Signal in favor of ‘secure’ state-developed alternative
Shift comes amid mounting reports of successful social engineering attacks targeting higher-ups in government This article has been indexed from www.theregister.com – Articles Read the original article: Poland directs officials to ditch Signal in favor of ‘secure’ state-developed alternative
F-35 software delays leave UK buying time with US glide bombs
MoD says StormBreaker will plug gap until homegrown SPEAR 3 integration lands This article has been indexed from www.theregister.com – Articles Read the original article: F-35 software delays leave UK buying time with US glide bombs
Mozilla warns UK: Breaking VPNs will not magically fix Britain’s age-check mess
Firefox maker says the tools are basic security infrastructure, not teenage contraband This article has been indexed from www.theregister.com – Articles Read the original article: Mozilla warns UK: Breaking VPNs will not magically fix Britain’s age-check mess
Grafana Labs admits all its codebase are belong to someone who popped its GitHub account
No customer info stolen, no impact to operations, and no blackmail payment This article has been indexed from www.theregister.com – Articles Read the original article: Grafana Labs admits all its codebase are belong to someone who popped its GitHub account
Linus Torvalds says AI-powered bug hunters have made Linux security mailing list ‘almost entirely unmanageable’
Multiple researchers using the same tools to find the same bugs are creating ‘unnecessary pain and pointless work’ This article has been indexed from www.theregister.com – Articles Read the original article: Linus Torvalds says AI-powered bug hunters have made Linux…
OpenAI caught in TanStack npm supply chain chaos after employee devices compromised
Attackers stole a limited amount of internal credential material after malware hidden in poisoned packages reached two staff machines This article has been indexed from www.theregister.com – Articles Read the original article: OpenAI caught in TanStack npm supply chain chaos…
MPs want social media treated more like unsafe toys than harmless apps
Parliamentary committee tells ministers the current online safety regime is failing children and warns ‘no action is not an option’ This article has been indexed from www.theregister.com – Articles Read the original article: MPs want social media treated more like…
Nobody believes the ‘criminals and scumbags’ who hacked Canvas really deleted stolen student data
Other than Instructure execs – maybe? This article has been indexed from www.theregister.com – Articles Read the original article: Nobody believes the ‘criminals and scumbags’ who hacked Canvas really deleted stolen student data
Cops arrest man suspected of being Dream Market kingpin
Owe Martin Andresen faces charges in both US and Germany connected with money laundering, claims he sent gold bars directly to his doorstep This article has been indexed from www.theregister.com – Articles Read the original article: Cops arrest man suspected…
Dirty Frag gets a sequel as Fragnesia hands Linux attackers root-level access
Fresh kernel flaw comes with public exploit code and continues ugly run of highly reliable privilege escalation bugs tied to memory and page-cache handling This article has been indexed from www.theregister.com – Articles Read the original article: Dirty Frag gets…
To gain root access at this company, all an intruder had to do was ask nicely
Human IT managers thought they were being nice to the boss, but were assisting a threat actor This article has been indexed from www.theregister.com – Articles Read the original article: To gain root access at this company, all an intruder…
AI models are getting better at replacing cybersecurity pros on certain tasks
UK researchers find LLMs are learning to finish jobs faster and improving all the time This article has been indexed from www.theregister.com – Articles Read the original article: AI models are getting better at replacing cybersecurity pros on certain tasks
Cisco to fire 4,000 staff and generously give them free training – on Cisco
Reducing memory requirements to control costs in a new wave of kit This article has been indexed from www.theregister.com – Articles Read the original article: Cisco to fire 4,000 staff and generously give them free training – on Cisco
Welcome to the vulnpocalypse, as vendors use AI to find bugs and patches multiply like rabbits
Palo Alto Networks found and fixed 75 flaws this month, up from its usual five This article has been indexed from www.theregister.com – Articles Read the original article: Welcome to the vulnpocalypse, as vendors use AI to find bugs and…