News

No login? No problem: Cisco ISE flaw gave root access before fix arrived, say researchers

The Register - Thu, 24/07/2025 - 19:28
Shadowserver claims miscreants were already poking at a critical hole in early July, long before Switchzilla patched it

Threat actors have actively exploited a newly patched vulnerability in Cisco's Identity Services Engine (ISE) software since early July, weeks before the networking giant got around to issuing a fix.…

Categories: News

So much for watermarks: UnMarker tool nukes AI provenance tags

The Register - Thu, 24/07/2025 - 18:45
Boffins insist your deepfake tracking tech won't work

Computer scientists with the University of Waterloo in Ontario, Canada, say they've developed a way to remove watermarks embedded in AI-generated images.…

Categories: News

Microsoft: SharePoint attacks now officially include ransomware infections

The Register - Thu, 24/07/2025 - 17:54
Let the games begin

Ransomware has officially entered the Microsoft SharePoint exploitation ring.…

Categories: News

Coyote malware abuses Microsoft's UI Automation to hunt banking creds

The Register - Thu, 24/07/2025 - 16:45
Some coyotes hunt squirrels, this one hunts users' financial apps

A new variant of the Coyote banking trojan abuses Microsoft's UI Automation (UIA), making it the first reported malware to use UIA for credential theft.…

Categories: News

The EFF is 35, but the battle to defend internet freedom is far from over

The Register - Thu, 24/07/2025 - 16:15
Palantir, data brokers, and judicial overreach are all on the horizon, executive director Cindy Cohn warns

Interview  In July 1990, before the World Wide Web even existed, an unusual alliance was formed to fight for the rights of the emerging online community.…

Categories: News

Compromised Amazon Q extension told AI to delete everything – and it shipped

The Register - Thu, 24/07/2025 - 15:26
Malicious actor reportedly sought to expose AWS 'security theater'

The official Amazon Q extension for Visual Studio Code (VS Code) was compromised to include a prompt to wipe the user's home directory and delete all their AWS resources.…

Categories: News

Eau no! Dior tells customers their data was swiped in cyber snafu

The Register - Thu, 24/07/2025 - 12:01
French fashion house dishes out notices after hackers raided a client database – ShinyHunters suspected

Updated  Fashion house Dior has begun dropping data breach notices after cybercrooks with a taste for high-end targets made off with customer data.…

Categories: News

Not pretty, not Windows-only: npm phishing attack laces popular packages with malware

The Register - Thu, 24/07/2025 - 11:01
The "is" package was infected with cross-platform malware after a scam targeting maintainers

The popular npm package "is" was infected with cross-platform malware, around the same time that linting utility packages used with the prettier code formatter were infected with Windows-only malware.…

Categories: News

IRL Com recruits teens for real-life stabbings, shootings, FBI warns

The Register - Wed, 23/07/2025 - 21:46
From scams to violence, the crimes extend beyond the digital realm

A subset of an online group that recruits children and teens for contract shootings, kidnappings, and other real-life violent crimes poses a growing threat to youth, according to the FBI.…

Categories: News

Nothing to see here: Brave browser blocks privacy-busting Microsoft Recall

The Register - Wed, 23/07/2025 - 21:15
No screenshots for you!

In an effort to protect user privacy, Brave browser 1.81 will prevent Microsoft Recall from screenshotting it by default.…

Categories: News

Microsoft SharePoint victim count hits 400+ orgs in ongoing attacks

The Register - Wed, 23/07/2025 - 19:05
US DOE among breached government agencies

More than 400 organizations have been compromised in the Microsoft SharePoint attack, according to Eye Security, which initially sounded the alarm on the mass exploitation last Friday, even before Redmond confirmed the critical vulnerabilities.…

Categories: News

VMware prevents some perpetual license holders from downloading patches

The Register - Wed, 23/07/2025 - 17:01
Despite pledging help for those who don’t sign for subs, Broadcom says validating their entitlements will delay support

Exclusive  Some customers of Broadcom’s VMware business currently cannot access security patches, putting them at greater risk of attack.…

Categories: News

Three questions you should always be able to answer about your security environment

The Register - Wed, 23/07/2025 - 16:00
All security questions are hard to answer, but these three are non-negotiable

Partner content  We've all seen those seemingly straightforward security questions that snowball into multi-day research projects across dozens of consoles, spreadsheets, and manual queries. The reality is that even the most fundamental security questions are notoriously difficult to answer with certainty.…

Categories: News

$380M lawsuit claims intruder got Clorox's passwords from Cognizant simply by asking

The Register - Wed, 23/07/2025 - 14:45
Hand us the mind bleach, we want to flush our memories of attack

Clorox is suing its service desk provider, Cognizant, for $380 million in a California state court, alleging the IT support crew "enabled a cybercriminal to gain a foothold in Clorox's network" by handing over staffers' passwords to attackers after they simply requested them.…

Categories: News

Copilot Vision on Windows 11 sends data to Microsoft servers

The Register - Wed, 23/07/2025 - 14:01
Total Recall: Capturing everything you do on your PC screen to become a 'true companion'

Microsoft is again throwing AI at Windows 11 to see what sticks, releasing features including the even more eyebrow-raising successor to its controversial Recall, a screen-streaming remotely processed backseat driver dubbed Copilot Vision.…

Categories: News

China warns citizens to beware backdoored devices, on land and under the sea

The Register - Wed, 23/07/2025 - 04:08
Suggests buying local tech to avoid infosec worries

China’s Ministry of State Security has spent the week warning of backdoored devices on land and at sea.…

Categories: News

Funding for program to stop next Stuxnet from hitting US expired Sunday

The Register - Tue, 22/07/2025 - 22:06
CyberSentry work grinds to a halt

Government funding for a program that hunts for threats on America's critical infrastructure networks expired on Sunday, preventing Lawrence Livermore National Laboratory from analyzing activity that could indicate a cyberattack, the program director told Congress on Tuesday.…

Categories: News

Arch Linux users told to purge Firefox forks after AUR malware scare

The Register - Tue, 22/07/2025 - 18:43
The distro's greatest asset is arguably also its greatest weakness

If you installed the Firefox, LibreWolf, or Zen web browsers from the Arch User Repository (AUR) in the last few days, delete them immediately and install fresh copies.…

Categories: News

Surprise, surprise: Chinese spies, IP stealers, other miscreants attacking Microsoft SharePoint servers

The Register - Tue, 22/07/2025 - 17:40
With more to come, no doubt

At least three Chinese groups are attacking on-premises SharePoint servers via a couple of recently disclosed Microsoft bugs, according to Redmond.…

Categories: News

Silicon Valley engineer admits theft of US missile tech secrets

The Register - Tue, 22/07/2025 - 17:13
Used stolen info to pitch for Chinese tech talent program

A Silicon Valley engineer has pleaded guilty to stealing thousands of trade secrets worth hundreds of millions of dollars, including crucial military technology.…

Categories: News

Pages

Subscribe to Sec Tec Limited aggregator - News