All the latest Tech/Sec news in one place!

Refresh Feeds
All Categories 253 Technology 98 Science 60 Security 50 Programming 20 Engineering 25
Mixed View Grouped by Category

Security (50 items)

CISA updated ransomware intel on 59 bugs last year without telling defenders

The register11 hours ago
GreyNoise's Glenn Thorpe counts the cost of missed opportunities On 59 occasions throughout 2025, the US Cybersecurity and Infrastructure Security Agency (CISA) silently tweaked vulnerability notices to reflect their use by ransomware crooks. Experts say that's a problem.…

Polish cops bail 20-year-old bedroom botnet operator

The register15 hours ago
DDoSer of 'strategically important' websites admitted to most charges Polish authorities have cuffed a 20-year-old man on suspicion of carrying out DDoS attacks.…

Notepad++ hijacking blamed on Chinese Lotus Blossom crew behind Chrysalis backdoor

The register1 days ago
The group targets telecoms, critical infrastructure - all the usual high-value orgs Security researchers have attributed the Notepad++ update hijacking to a Chinese government-linked espionage crew called Lotus Blossom (aka Lotus Panda, Billbug), which abused weaknesses in the update infrastructure ...

Russia-linked APT28 attackers already abusing new Microsoft Office zero-day

The register1 days ago
Ukraine’s CERT says the bug went from disclosure to active exploitation in days Russia-linked attackers are already exploiting Microsoft's latest Office zero-day, with Ukraine's national cyber defense team warning that the same bug is being used to target government agencies inside the country and...

Notepad++ update service hijacked in targeted state-linked attack

The register1 days ago
Breach lingered for months before stronger signature checks shut the door A state-sponsored cyber criminal compromised Notepad++'s update service in 2025, according to the project's author.…

Infrastructure cyberattacks are suddenly in fashion. We can buck the trend

The register1 days ago
Don't be scared of the digital dark – learn how to keep the lights on Opinion  Barely a month into 2026, electrical power infrastructure on two continents has tested positive for cyberattacks. One fell flat as attempts to infiltrate and disrupt the Polish distribution grid were rebuffed and repor...

Thousands more Oregon residents learn their health data was stolen in TriZetto breach

The register4 days ago
Parent company Cognizant hit with multiple lawsuits Thousands more Oregonians will soon receive data breach letters in the continued fallout from the TriZetto data breach, in which someone hacked the insurance verification provider and gained access to its healthcare provider customers across multip...

To stop crims, Google starts dismantling residential proxy network they use to hide

The register5 days ago
The Chocolate Factory strikes again, targeting the infrastructure attackers use to stay anonymous Crims love to make it look like their traffic is actually coming from legit homes and businesses, and they do so by using residential proxy networks. Now, Google says it has "significantly degraded" wha...

ShinyHunters swipes right on 10M records in alleged dating app data grab

The register5 days ago
Extortion crew says it's found love in someone else's info as Match Group plays down the impact ShinyHunters has added a fresh notch to its breach belt, claiming it has pinched more than 10 million records from Match Group, a US firm that owns some of the world's most widely used swipe-based dating ...

Cyberattack on Poland's power grid could have turned deadly in winter cold

The register5 days ago
Close call after an apparently deliberate attempt to starve a country of energy at the worst time Cybersecurity experts involved in the cleanup of the cyberattacks on Poland's power network say the consequences could have been lethal.…

Ransomware crims forced to take off-RAMP as FBI seizes forum

The register6 days ago
Cybercrime solved. The end Ransomware crims have just lost one of their best business platforms. US law enforcement has seized the notorious RAMP cybercrime forum's dark web and clearnet domains.…

Everybody is WinRAR phishing, dropping RATs as fast as lightning

The register6 days ago
Russians, Chinese spies, run-of-the-mill crims … Come one, come all. Everyone from Russian and Chinese government goons to financially motivated miscreants is exploiting a long-since-patched WinRAR vuln to bring you infostealers and Remote Access Trojans (RATs).…

Let them eat sourdough: ShinyHunters claims Panera Bread as stolen credentials victim

The registerJan 27, 2026
Plus, the gang says it got in via Microsoft Entra SSO ShinyHunters says it stole several slices of data from Panera Bread, but that's just the yeast of everyone's problems. The extortionist gang also claims to have stolen data from CarMax and Edmunds, in addition to three other organizations it post...

China-linked group accused of spying on phones of UK prime ministers' aides – for years

The registerJan 27, 2026
Reports say Salt Typhoon attackers accessed handsets of senior govt folk Chinese state-linked hackers are accused of spending years inside the phones of senior Downing Street officials, exposing private communications at the heart of the UK government.…

Canva among ~100 targets of ShinyHunters Okta identity-theft campaign

The registerJan 26, 2026
Atlassian, RingCentral, ZoomInfo also among tech targets ShinyHunters has targeted around 100 organizations in its latest Okta single sign-on (SSO) credential stealing campaign, according to researchers and the criminal group itself.…

Data thieves borrow Nike's 'Just Do It' mantra, claim they ran off with 1.4TB

The registerJan 26, 2026
US sports brand launches probe after extortion crew WorldLeaks claims it stole huge dataset Nike says it is probing a possible breach after extortion crew WorldLeaks claimed to have lifted 1.4TB of internal data from the sportswear giant and posted samples on its leak site.…

Moscow likely behind wiper attack on Poland’s power grid, experts say

The registerJan 26, 2026
Cyber sleuths believe Sandworm up to its old tricks with a brand-new sabotage toy Russia was probably behind the failed attempts to compromise the systems of Poland's power companies in December, cybersecurity researchers claim.…

ShinyHunters claims Okta customer breaches, leaks data belonging to 3 orgs

The registerJan 23, 2026
'A lot more' victims to come, we're told ShinyHunters has claimed responsibility for an Okta voice-phishing campaign during which the extortionist crew allegedly gained access to Crunchbase and Betterment.…

London boroughs limping back online months after cyberattack

The registerJan 23, 2026
Direct debits? Maybe February. Birth certificates? Dream on. Council tax bills? Oh, those are coming Hammersmith & Fulham Council says payments are now being processed as usual, two months after a cyberattack that affected multiple boroughs in the UK's capital city.…

Crims hit the easy button for Scattered-Spider style helpdesk scams

The registerJan 22, 2026
Teach a crook to phish… Criminals can more easily pull off social engineering scams and other forms of identity fraud thanks to custom voice-phishing kits being sold on dark web forums and messaging platforms.…

Crims compromised energy firms' Microsoft accounts, sent 600 phishing emails

The registerJan 22, 2026
Logging in, not breaking in Unknown attackers are abusing Microsoft SharePoint file-sharing services to target multiple energy-sector organizations, harvest user credentials, take over corporate inboxes, and then send hundreds of phishing emails from compromised accounts to contacts inside and outsi...

FortiGate firewalls hit by silent SSO intrusions and config theft

The registerJan 22, 2026
Admins say attackers are still getting in despite recent patches FortiGate firewalls are getting quietly reconfigured and stripped down by miscreants who've figured out how to sidestep SSO protections and grab sensitive settings right out of the box.…

Don't click on the LastPass 'create backup' link - it's a scam

The registerJan 21, 2026
Phishing campaign tries to reel in master passwords updated  Password managers make great targets for attackers because they can hold many of the keys to your kingdom. Now, LastPass has warned customers about phishing emails claiming that action is required ahead of scheduled maintenance and told t...

Everest ransomware gang said to be sitting on mountain of Under Armour data

The registerJan 21, 2026
Have I Been Pwned reckons 72.7M customer accounts affected, sportswear firm remains silent Have I Been Pwned (HIBP) says 72.7 million accounts registered with Under Armour were affected by an alleged ransomware attack in November.…

Akamai CEO wants help to defeat piracy, reckons he can handle edge AI alone

The registerJan 20, 2026
OG CDN boss says fighting illegal streams is about stopping criminals cashing in, not free speech Interview  When Cloudflare CEO Matthew Prince recently threatened to disrupt the Winter Olympics to protect free speech after Italian authorities fined his company for not disrupting pirate video strea...

Broker who sold malware to the FBI set for sentencing

The registerJan 19, 2026
Feras Albashiti faces 10 years after $20,000 in sales to undercover agent exposed ransomware ties A Jordanian national faces sentencing in the US after pleading guilty to acting as an initial access broker (IAB) for various cyberattacks.…

Don't underestimate pro-Russia hacktivists, warns UK's cyber crew

The registerJan 19, 2026
They’re not the most sophisticated, but even simple attacks can lead to costly consequences The UK's National Cyber Security Centre (NCSC) is once again warning that pro-Russia hacktivists are a threat to critical services operators.…

Ingram Micro admits summer ransomware raid exposed thousands of staff records

The registerJan 19, 2026
Maine filing confirms July attack affected 42,521 employees and job applicants Ingram Micro disclosed that a July 2025 ransomware attack compromised the personal data of tens of thousands of employees.…

Warwickshire school to reopen after cyberattack crippled IT

The registerJan 19, 2026
Kids return to classrooms after safety infrastructure knocked out A Warwickshire secondary school says it will fully reopen this week after a cyberattack forced a prolonged closure – though staff will return to classrooms with "very limited access" to IT systems.…

German cops add Black Basta boss to EU most-wanted list

The registerJan 16, 2026
Ransomware kingpin who escaped Armenian custody is believed to be lying low back home German cops have added Russian national Oleg Evgenievich Nefekov to their list of most-wanted criminals for his services to ransomware.…

RondoDox botnet linked to large-scale exploit of critical HPE OneView bug

The registerJan 16, 2026
Check Point observes 40K+ attack attempts in 4 hours, with government organizations under fire A critical HPE OneView flaw is now being exploited at scale, with Check Point tying mass, automated attacks to the RondoDox botnet.…

Chinese spies used Maduro's capture as a lure to phish US govt agencies

The registerJan 15, 2026
What's next for Venezuela? Click on the file and see What policy wonk wouldn't want to click on an attachment promising to unveil US plans for Venezuela? Chinese cyberspies used just such a lure to target US government agencies and policy-related organizations in a phishing campaign that began just ...

Microsoft taps UK courts to dismantle cybercrime host RedVDS

The registerJan 15, 2026
Redmond says cheap virtual desktops powered a global wave of phishing and fraud Microsoft has taken its cybercrime fight to the UK in its first major civil action outside the US, moving to shut down RedVDS, a virtual desktop service used to power phishing and fraud at global scale.…

France fines telcos €42M for sub-par security prior to 24M customer breach

The registerJan 14, 2026
Three major GDPR violations, including a lack of basic security controls, lead to hefty dent in profits The French data protection regulator, CNIL, today issued a collective €42 million ($48.9 million) fine to two French telecom companies for GDPR violations stemming from a data breach.…

'Imagination the limit': DeadLock ransomware gang using smart contracts to hide their work

The registerJan 14, 2026
New crooks on the block get crafty with blockchain to evade defenses Researchers at Group-IB say the DeadLock ransomware operation is using blockchain-based anti-detection methods to evade defenders' attempts to analyze their tradecraft.…

Cyber-stricken Belgian hospitals refuse ambulances, transfer critical patients

The registerJan 14, 2026
Attack enters second day with major disruption to healthcare provision Two hospitals in Belgium have cancelled surgeries and transferred critical patients to other facilities after shutting down servers following a cyberattack.…

Eurail passengers taken for a ride as data breach spills passports, bank details

The registerJan 14, 2026
Travel biz tells customers to change passwords beyond its own services Eurail has confirmed customer information was stolen in a data breach, according to notification emails sent out this week.…

Spanish power giant sparks breach probe amid claims of massive data grab

The registerJan 14, 2026
Endesa says payment info stolen after alleged crook boasted of 1 TB-plus haul Spanish energy giant Endesa is warning customers about a data breach after a cybercrim claimed to have walked off with a vast cache of personal information allegedly tied to more than 20 million people.…

Dutch cops cuff alleged AVCheck malware kingpin in Amsterdam

The registerJan 13, 2026
33-year-old was under surveillance for some time before returning home from the UAE Dutch police believe they have arrested a man behind the AVCheck online platform - a service used by cybercrims that Operation Endgame shuttered in May.…

Court tosses appeal by hacker who opened port to coke smugglers with malware

The registerJan 13, 2026
Dutchman fails to convince judges his trial was unfair because cops read his encrypted chats A Dutch appeals court has kept a seven-year prison sentence in place for a man who hacked port IT systems with malware-stuffed USB sticks to help cocaine smugglers move containers, brushing off claims that p...

'Violence-as-a-service' suspect arrested in Iraq, extradition underway

The registerJan 12, 2026
Gang members 'systematically exploited children and young people,' cops say A 21-year-old Swedish man accused of being a key organizer of violence-as-a-service linked to the Foxtrot criminal network, which police say has recruited and exploited minors, has been arrested in Iraq.…

Infamous BreachForums forum breached, spilling data on 325K users

The registerJan 12, 2026
Website built around buying and selling stolen data has lost control of its own Updated  BreachForums, the serially resurrected cybercrime marketplace, has tripped over itself after a data breach spilled details tied to about 324,000 user accounts.…

Meta admits to Instagram password reset mess, denies data leak

The registerJan 11, 2026
PLUS: Veeam patches critical vuln; Crims bribing dark web insiders; UK school takedown; And more infosec in brief  Meta has fixed a flaw in its Instagram service that allowed third parties to generate password reset emails, but denied the problem led to theft of users’ personal information.…

UK government exempting itself from flagship cyber law inspires little confidence

The registerJan 10, 2026
Ministers promise equivalent standards just without the legal obligation ANALYSIS  From May's cyberattack on the Legal Aid Agency to the Foreign Office breach months later, cyber incidents have become increasingly common in UK government.…

Putinswap: France trades alleged ransomware crook for conflict researcher

The registerJan 9, 2026
Basketball player accused of aiding cybercrime gang extradition blocked in exchange for Swiss NGO consultant France has released an alleged ransomware crook wanted by the US in exchange for a conflict researcher imprisoned in Russia.…

QR codes a powerful new phishing weapon in hands of Pyongyang cyberspies

The registerJan 9, 2026
State-backed attackers are using QR codes to slip past enterprise security and help themselves to cloud logins, the FBI says North Korean government hackers are turning QR codes into credential-stealing weapons, the FBI has warned, as Pyongyang's spies find new ways to duck enterprise security and h...

China-linked cybercrims abused VMware ESXi zero-days a year before disclosure

The registerJan 9, 2026
Huntress analysis suggests VM escape bugs were already weaponized in the wild Chinese-linked cybercriminals were sitting on a working VMware ESXi hypervisor escape kit more than a year before the bugs it relied on were made public.…

Ransomware attacks kept climbing in 2025 as gangs refused to stay dead

The registerJan 8, 2026
Cop wins hit crime infrastructure, not the people behind it If 2025 was meant to be the year ransomware started dying, nobody appears to have told the attackers.…