os platforms Debian's latest kernel security update has 1,313 reasons to patch AI-assisted bug hunting adds to maintainers' workload, while broad CVE rules help explain the sprawling tally
security Legacy sign-on service comes back to bite school software provider Bromcom Intruders retrieved email addresses from superseded tech kept running for an internal system
security Anthropic's super bug-hunting model Mythos is hardcore good at math, as latest vuln under attack shows Exploitation attempts came from China-hosted IP, VulnCheck researcher says
security OpenAI alerts 100+ orgs that its 'misaligned models' attempted to break in - or worse Mostly 'routine research tasks,' and 'some involved government websites, which our models often use,' AI giant tells The Reg
security Californian accused of shipping $300M worth of Nvidia chips to China without Uncle Sam’s approval Prosecutors claim Greg Lui helped China procure advanced hardware to develop, ahem, 'super intelligence’
ai and ml OpenAI's wandering AI agents earn it a California subpoena Plus: Attorneys-general say investigators should have direct access to AI companies' records when things go wrong
security Fortinet sounds the alarm over actively exploited FortiMail zero-day No login required, exploitation underway, and some admins are still waiting for patches
security AI agents hacked the hackers, stealing email addresses from security research org Chained Zammad flaws enabled session hijacking, code execution, and root escalation in seconds
security EU’s hodgepodge tech policy exposes members to Chinese vendor risks, says think tank RUSI wants procurement rethink that could put US suppliers under scrutiny too
security Suspected Chinese spies spoofed an Anthropic exec, ex-White House official in AI phishing Your invite to a fake AI policy advisory committee has strings attached
security Microsoft catches hackers exploiting Zimbra bug before disclosure Attackers were probing the mail server flaw weeks before it had a CVE to its name
security MI5 warns UK academics their research may have helped Chinese spies Institutions told to trace who is really financing their work or risk falling foul of national security law
security CISO thought he had a 'r3@lg00dp@$$w0rd' but forgot to patch Replacing letters with symbols still doesn’t make it good.
security England's schools are getting better at mopping up cyber incidents Two-thirds report immediate recovery, although teachers remain divided over whose job security is
security UK privacy watchdog starts over with new board and Manchester HQ The Information Commission replaces the Information Commissioner, putting statutory powers under collective control
security Fewer women than ever in UK's 'old boys' club' cyber industry Younger workers often overlooked for senior roles due to historical issues and fears they’ll get pregnant, says survey
security Irony alert: OpenAI whines that Chinese model stole its special IP that it stole from everybody else US model makers can train on web data - but distilling theirs is a 'national security risk'
security 16-year-old researcher found a Microsoft bug, got admin access to databases with 17.3 trillion rows It's 2 am. Do you know what your teen is doing?
security More than half of UK businesses lack confidence in basic cyber skills Government survey puts the figure at 808k, says detecting and removing malware most common weakness
security UK rail cops' £320K face-scanning spree nets zero matches British Transport Police’s six-month facial recognition pilot produced one alert, and it was a false positive
security Spectre bug is back, this time to haunt JIT engines Researchers find a way to recover stale indirect branch prediction entries
security Add one more AI worry to the nightmare scenario: self-replicating prompt injections It's a worm attack, AI-style
security FBI to ShinyHunters: 'We know how to find you' Federal cops have 'a very particular set of skills'
security Custom malware used in Citrix 0-day attacks targeting govt, banks, professional services Two questions remain: who is abusing the CVEs? And why did Citrix take so long to disclose?
ai and ml AI models keep posting screenshots showing sensitive data from inside tech companies Glow Security finds more than 13,000 publicly accessible images that expose corporate development work
security Apple patches CoreGraphics zero-day already exploited in targeted attacks Meta-spotted flaw could hand attackers arbitrary code execution via a maliciously crafted file
ai and ml OpenAI benches GPT-6.1 Astra for overstepping the mark Turns out teaching an AI to keep going can make it rather bad at knowing when to stop
security Former X-Force hackers chase the offensive cyber gold rush RemoteThreat launches with $7M, 1,000 attack tools, and ambitions to equip enterprises and Uncle Sam for AI-speed operations
ai and ml OpenAI’s dirty deeds Down Under included security bypass attempts, using exposed keys, source code siphon Admits its agents side-swiped four Australian government sites
security JadePuffer crims hijacked Azure identities and used them to blow up cloud resources Smells like more agentic ransomware, Redmond warns
cyber-crime Ex-soldier's telecom hacking spree earns him 70 months Active-duty campaign targeted at least ten organizations and sought $1 million in ransom payments
security Certainties in life: Death, taxes, and critical Citrix vulns under attack Sunday NetScaler patch dump fixes trio of critical vulns and five more serious messes
ai and ml OpenAI pauses some training amid allegations its rogue agents behaved more badly than first thought Amid allegations that agents may have gone off the rails thousands of times, China set up some kind of agentic incident hotline
security Fake Google Security Team ad says 'no script reading' in voice phishing - then prints the script More mockery and memes from the Dark Web Roast
cyber-crime ShinyHunters tells The Reg: We hacked the FBI to 'protect our business' Data theft and extortion biz, that is
security Crooks use fake desktop apps to fool HR staff into giving them remote access Nothing in the attack chain screams malicious software, except none of the impersonated HR and payroll providers actually offers a desktop app
cyber-crime Bitget blames North Korea for $387.5M crypto wallet raid Familiar fingerprints point to Kim’s regime … to the surprise of nobody
storage Which copy of that file is the real one? Dinner, off the record, in Midtown Joe Fay chairs a Register dinner in New York on the file infrastructure nobody has got around to replacing, with nothing on the record.
security Crook used three open source agents to break into a Fortune 500 hospitality company, a major US airline and 25+ other orgs Operator’s AI bill averaged just $25 per completed scan
security Salesforce Agentforce vulns allowed 0-click CRM data theft, anonymous phishing 'SalesBleed' security flaws 'lead to very unexpected consequences'
security Decades-old file security flaws found in Android, Linux, macOS, and Windows Security researchers report that Microsoft considers the side-channel leak of file events to be by design
os platforms CVE flood pushes Ubuntu onto weekly kernel release cycle AI-assisted bug hunting is helping pile up vulnerabilities faster than defenders can patch them, so Canonical is picking up the pace
security Someone went shopping in ASUS's eShop – for customer data Contact details and order records accessed, but PC maker is keeping schtum on how many customers are affected
security Google to critical infra orgs: Our AI scanners won't be evil, promise Gemini 3.8 Flash Cyber and Wiz's Red Agent team up to protect hospitals, public transit, and tech
security Government contractor exposed path to immigration records IT took a shortcut when the boss was away, and it led to danger!
security OpenAI agents ‘infiltrated Australian government website’ Canberra is fuming after AI lab sent the news to a generic unattended email address
Someone's attacking a critical 0-day RCE in F5 BIG-IP APM Good news: there's a patch. Bad news: both CISA and F5 warn that it's under active exploitation
Academic publisher Elsevier hit by LAPSUS$ redirect attack Customers got crime crew's calling card instead of access to journals
security Closing the observability gap for the AI-ready enterprise SPONSORED FEATURE: Why AI-driven operations need a data-rich view of the network
security British regulator takes a hard look at Pornhub's Apple-powered age checks Regulator wants to know whether parent Aylo did its homework before reopening the door to UK iPhone users
security Why security belongs in the network SPONSORED EXPLAINER: Merging security into the network makes enterprise protection more agile
security Windows CLOSEDQUORUM malware uses AI models to autonomously select post-compromise actions 'first' publicly documented Windows implant to use LLMs for C2
security NightmareEclipse's latest zero-day leaves Microsoft Defender stuck in the past BigDiskBuster leaves Microsoft's antivirus running but unable to install updates
Z.ai says sorry for slurping up your code, open sources ZCode China’s AI darling goes on the defense after engineer highlighted Grok-esque security flaws
security UK cops arrest 2 EvilTokens suspects, Microsoft seizes 50 phishing kit websites Used by crims to compromise 12K+ email inboxes across 10K+ global orgs
security Who signed off on that AI agent? Nobody? Thought so. SPONSORED FEATURE: AI agents may be unpredictable. Who they are, what they can do, and who owns them shouldn’t be.
security Anthropic-linked CVEs pile up, attackers mostly shrug Of 225 flaws found by Glasswing and tracked by VulnCheck researcher, just one has confirmed exploitation in the wild
ai and ml Meta Muse AI app flaw lets local malware redirect dictation traffic Ad biz promises users control while bug could expose voice prompts
security Treasury chief says AI bosses, not their bots, will carry the can for criminal acts 'Humans are responsible, not the AI,' argues Scott Bessent as he calls out OpenAI agents' hack of Hugging Face
cyber-crime Clop gets a taste of its own medicine after ShinyHunters hijack leak site Rival crew demands eight figures and threatens to expose companies that paid to keep quiet
security Rustaceans warned of job interviews with a malicious payload Attackers are courting crate owners with plausible company profiles and booby-trapped recruitment calls
security Agentic security is the billion-dollar challenge for some clever startup to solve High time to stop kicking the security can down the road, investor tells The Reg
security Researchers used Claude to hack OpenAI employees' ChatGPT accounts Agentic exploits for the win (again)
security North Korea's fake job interviews infected 30,000 devices WaterPlum recruiters used bogus coding tests to backdoor jobseekers and raid more than 7,000 crypto wallets
cyber-crime FBI: Fake cop and government impersonation scams cost victims $1.6B AI, fake uniforms, and mock offices help crooks sell the con
security USA’s Venezuela takeover comes with bonus exposure to Chinese AI surveillance tech Think tank points out that companies banned by Washington will help run the regime that Uncle Sam now controls
security AI coding agents' 0-click RCE flaw could hand attackers keys to the kingdom Plugin4Shell attack affects all the major coding agents, researchers say
security Researchers find way to listen in on headphones from afar Eve's dropping in on Alice and Bob
security China's Salt Typhoon backdoors Latin American orgs with new snooping malware Beware the SparroWocky, my son! The backdoor that bites…
security London property manager breach may have exposed bank details and lockbox codes City Relay says intruders accessed its Metabase Cloud instance twice and extracted customer data
security Cisco drops another exploited zero-day, this time a perfect 10 ISE authentication bypass under active attack just days after another Cisco zero-day sent admins scrambling to patch
security Test environment let anyone access live customer data Even a temporary staging server needs to be locked down.
security Ofcom discovers issuing Online Safety Act fines is easier than collecting them Platforms comply just enough to avoid being blocked, leaving the regulator chasing debt
security AI agents can modify themselves without humans telling them to do so This is a test - it is only a test
security CISA decides weekly vulnerability bulletin isn't necessary anymore Agency's shift from static CVSS scores to risk-based prioritization sends the old format packing September 28
security Google Pixel phones pwned in zero-click attacks CISA gives federal agencies just 3 days to patch
cyber-crime Spain gets its first taste of AI-aided cyber attack Data protection chiefs call for 'immediate review' of data protection models
security Ministry of Justice apologizes after court staff accessed Southport victims' files Sensitive personal data was involved, but there is no evidence it was shared with third parties
security Mythos has made 2026 patching hell. It might make 2027 a breeze Gartner sees huge amounts of technical debt paid down, and better scanning that could make software safer sooner
security The vulnpocalypse rains iBugs down on Apple with record-setting number of patches September Patch Tuesday part 2?
security Low-quality casino sites conceal highly dangerous threat actors Security firm Infoblox shines light on malicious infrastructure lurking beneath illegal gambling sites
security Iranian spies hit Windows machines with Chosen Brick data-stealing malware 'Enemies of the regime' on notice
security Cisco email security boxes can be rooted by... an email Attackers already exploiting the critical flaw, and Cisco warns they may be able to cover their tracks once they're in
security Who's governing your AI? A trust framework for enterprise agents and models SPONSORED FEATURE: DigiCert wants to hand every agent a passport, an expiry date and a named human owner
security Swiss court sentences 52-year-old Ukrainian ransomware dev to nearly 13 years in the cooler The man allegedly wrote the code that powered the Lockergoga, MegaCortex, and Nefilim operations
ai and ml The latest AI doomsayer is China’s intelligence boss Beijing’s response is to ‘firmly grasp technological sovereignty’ and broad regulations
cyber-crime HBO Max Reddit account compromised to serve ClickFix attacks Part of a 'massive 48-hour malvertising blitz' targeting macOS and Windows machines with malware
security New hardware device can RAM into encrypted memory, expose your data Attackers would need physical access to the server to pull off the DDR5 trick
security OpenAI's malicious bot swarm attacked RubyGems Ruby are you ok? Ruby are you ok? Are you ok Ruby?
security Perfect-10 GitLab bug under attack days after patch lands CISA confirms active exploitation as watchTowr spots miscreants probing internet-facing servers
security UK.gov begins killing off passwords for 23 million users Passkeys promise fewer phishing headaches – and £600 a day off Whitehall's SMS bill
ai and ml Latest Anthropic horror story chills with tales of kamikaze drone swarms and bioweapons research
security Dental contractor set up secret account with access to 4,000 patient records then left the company
ai and ml Rogue OpenAI agents used dead German web site to communicate in May, months before Hugging Face incident
security Terminated employee cost company hundreds of thousands of dollars because nobody revoked access
security AI agents carried out every step of this ransomware attack – then left the victim an 80-page security audit
cyber-crime Cops, CrowdStrike disrupt Sality botnet by poisoning the network and diverting into sinkholes
security FBI seizes hacking tools it says China used to attack NASA, DOE, US Senate and other critical networks
security AliExpress accused of fingerprinting shoppers with silent audio trick that also muted a dev's headphones
security 'Not a theoretical risk,' feds warn as attackers use AI-made code to hack critical infrastructure controllers
security Stopping a cyberattack while walking your dog - defensive AI security CEO says it's not ruff to do