AI agent suggested installing a malware package. Engineer almost took its advice Fortunately, the company had a policy of checking source code on GitHub first
'Not a theoretical risk,' feds warn as attackers use AI-made code to hack critical infrastructure controllers 'It is an active threat'
ICE boss to agents: Leave the Meta spy glasses at home 'Personally owned body-worn cameras are prohibited,' ICE tells The Reg. Because the last thing DHS needs is more proof of misconduct
Flock surveillance backlash mounts as fiendish Halloween plans circulate CEO apologizes for police misuse as activists call for vandal action against license plate cameras
Comcast gives its Wi-Fi motion detector a security makeover Rebranded feature promises household alerts without video, but mind the small print
Australian hotel chain leaks guests’ PII after breach at third-party database operator Unknown parties know where you stayed last summer, down under, across 120 Quest properties
OpenAI's overhead will rise 20 percent for some workloads as it hardens security Expanded multistage chain of thought monitoring makes frontier model work more expensive
Expired credit cards revived by researchers to make unauthorized payments Gaps in expiry checks could let dead plastic make purchases again
CISA gives feds 3 days to fix actively exploited Ray RCE bug Phishing, malvertising attacks could target devs to gain access to private corporate networks
Apple plugs image-processing hole ripe for spyware abuse Patch batch spans current kit, older iGadgets, Macs, and Vision Pro
Copilot tricked into telling reseachers how to hack itself How to social engineer an AI's reasoning engine
Crook hawks millions of records allegedly plundered from corporate Azure tenants McDonald's, Vodafone, TCS, Kyndryl, and others named as researchers point to compromised credentials
Code fixers have fired up the AI warp drive. Strange new worlds await With more patches per month than at a pirate convention, the bug must be an endangered species. Well, about that
Black Hat and DEF CON are AI conferences now, too On this week's episode of The Reg's Kettle podcast, we revisit 'hacker summer camp,' where the hottest topic was ... sigh... agentic AI
Microsoft blames AI for delayed Exchange update, can’t say when it will arrive Dealing with machine-made bug backlog makes it hard to find a moment to deliver promised subscription service
Chinese AI company Zhipu claims its new model is a better bug-finder than Anthropic, OpenAI PLUS: HCL, TCS, admit data breaches; South Korea to fine Apple, Google; India bans some rideshare tips; and more!
Stopping a cyberattack while walking your dog - defensive AI security CEO says it's not ruff to do Corma CEO tells The Reg it's building 'One ring to rule them all, for the defenders to have this power'
ChainDrop worm crawls into npm supply chain, evades standard defenses Shai-Hulud variant poisons 444 packages, spreads via tarballs and dev-tool hooks
1.6M RingCentral accounts' data dumped after ShinyHunters extortion attack Another one bites the dust
French tax authority admits data heist after crook touts 2M records Government disputes claims of continued access as investigators measure damage
Autonomous AI attacks pose 'clear and present danger' to critical infrastructure Weaponized agents could turn digital intrusions into kinetic disasters, experts warn
Crypto wallet maker Trezor confirms 13,000 customers' details exposed in logistics breach Even if your hardware is secure, quantum-ready, encrypted, and future-proof, no one is immune to a supplier letting the side down
Scottish prosecutors cast eye over leaky supplier after staff data exposed Unnamed third party spotted suspicious activity, with names, roles, and email addresses potentially affected
New Zealand says China tried using space investments to spy on local affairs Intelligence Service says finding domestic threats is harder due to proliferation of toxic content online
OpenAI ditches Recall-style screenshot surveillance for friendly keylogging 'Computer History' records clicks and typing to build ChatGPT memories
Trump wants to grant private cyber firms a license to hack back Contractors could surveil and disrupt foreign criminal networks, provided they follow strict rules and put up $1M
Mystery attacker spent a year raiding Salesforce and ServiceNow portals Custom tools harvested whatever over-permissioned guest accounts would surrender
AWS key exposed in JavaScript may have lit way to Beacon's charity data CRM provider confirms customer database was copied and probably downloaded in readable form
Passwords stored in public Google Doc then showed up in search results Developer spotted hostname and credential string lurking in autocomplete
Chinese Loongson processors have leaky caches, researchers find Attackers could extract data, even working from inside a guest VM
'Near-autonomous' AI agents attack Taiwan's nuclear safety agency Some say the world will end in fire, some say an agentic swarm
Spectre rears its ugly head again as researchers show some RISC-V chips are susceptible Eight years on, we're still paying to hide the future glimpsed during speculative execution
Microsoft-vendetta hacker has a new zero day that gives system privileges on fully patched Windows Exploit Wednesday's back, baby
Smooth-talking fraudsters clone contactless cards, authorize payments in just 13 minutes Social engineering and malware combine to enable financial fraud before banks have time to act
Uber Freight keeps on trucking after extortion crew breaks in Helix claims nearly a million files, while the logistics biz says operations never hit the brakes
Exposed: Woeful security at UK criminal records office that led to sensitive data leak Nobody patched the CMS or read the alerts, and ACRO still cannot tell whether info was exfiltrated
Akira ransomware scum blocked victim's security tools – and broke their own encryptor Gives a whole new meaning to Safe Mode
Brit rail cops bring live facial recognition to the London Underground Victoria is the first stop as privacy campaigners warn the technology is becoming routine
Signal adds an extra layer of security to make sure you're actually chatting with the right person One big caveat, though: You need your contact's phone number
421 bugs in Microsoft's Patch Tuesday release, and the Norks have already attacked one Sysadmins, welcome to your new norm
DEF CON dingus suspected of trying to take over Delta in-flight Wi-Fi This is why we can't have nice things, people
Two wars and a World Cup lead to epic DDoS attacks on publishers Ukraine, Iran, and football inspire geopolitically motivated DDoS attacks, while 1 Tbps traffic jams up 519 percent
Feds warn Gunra ransomware is exploiting known bugs to hit critical infrastructure Newly minted RaaS crew breaks in through using internet-facing kit via known Fortinet flaws, then steals and scrambles data
Cyberattack on logistics giant CEVA delivers customer data into the wrong hands Valve, Bol, ING, Ajax, and others affected as pwnage disrupts eight European warehouses
Deepfake hiccup unmasks suspected digital certificate fraudster Face-swap software blinked for 'barely a second,' giving Spanish cops the break they needed
Mozilla revokes Firefox signing key after unencrypted copy lands in GitHub Audit logs found no unexpected visitors, but release verification still needs an update
Malicious SIMs can shut down phones, steal files, and drag 5G back to 2G Researchers find standards-compliant functionality can be abused to hijack modems, downgrade connections, and even execute code
DEF CON hackers add new muscle to water utility protection Franklin project adds new security providers, employs digital twins and AI
North Korean spies are running local LLMs to cause AI mischief Kimsuky's phishing attacks get an AI boost
Gym rat asks AI agent to book him a class, it hacks a waitlist API to bump him up the list What wouldst thou ask of the monkey's paw?
Attackers pick Levi's pockets in social engineering attack Crims talked their way onto three employee PCs before trousering corporate data
Wetherspoons bars smart glasses from filming customers Pub chain says turn off the cameras, reminds punters not to blare sound from phone vids either
Cyber vulnerability sweep picks up Royal Navy drones sending data to China No, no nasties to see here, guv...
Framework loses customer data in Metabase zero-day attack Repairable hardware is little comfort when personal details escape
Claude Code puts auto mode in the driver's seat Walk away and hope the classifier catches anything irreversible or destructive
Advertisers are trying to influence AI bots with secret ads PLUS: Hiveminds are emerging to hack the planet, and open-weight models are the new new red scare
Ransomware gangs skip the CEO, head straight for the 40-something IT manager Gen Xers who feel triggered by this should remember to unplug the network cable and call the cops
Devs to Anthropic, OpenAI, Cursor, and friends: Make security and privacy the default Researchers scour social media to measure developer concerns about AI coding tools
OpenAI pledges to add Astra security as Anthropic loosens Fable's leash Or how I learned to stop worrying and love dangerous AI
Water system controllers don't belong on the internet, says ex-NSA chief after suspected Iran attacks Calling all defenders
Ransomware attacks spike as world distracted by AI What, you didn't think the top gangs were busy watching agents escape their sandboxes too, did you?
N-able God mode flaw: Vendor confirms attackers reached customer networks as second hotfix lands Attackers turned admin access into a route downstream, while N-able tells N-central customers to patch – again
ShinyHunters called cancer diagnostics biz and tricked staffers into giving them access. Now they've dumped 10.9M email addresses Cancer diagnostics breach spills personal and health info as extortion crew says healthcare giant ‘should’ve paid the ransom’
MIT boffins' TONTOU attack slips through Spectre defenses on Intel and AMD CPUs Timer interrupts reopen branch predictor poisoning window, with a working Zen 2 exploit to prove it
Scot NHS trust probes access to medical records of 9-year-old girl after man arrested on suspicion of murder Investigation into whether staff improperly accessed Minnie Merriman’s file after she was named for the first time this week
Attacker phished way into US defense supplier's Microsoft 365 account Intruder gained access to engineering files and potentially export-controlled technical data
Intrusion at US healthcare software provider puts 3.8M people's data at risk Unlimited Technology Systems says names, Social Security numbers, diagnoses, and insurance details may have been swiped
'Asimov was right' about rules for robots, says ex-US Cyber Director Humans will get the AI models they deserve
China launches mysterious probe into security of Palo Alto Networks' products Beijing’s not saying why, which is just what happened when it investigated Micron
How the famed USENIX Security conf is managing a flood of papers in the AI era AI usage is evident but isn't yet a serious problem