❌

Normal view

Received β€” 16 January 2026 ⏭ The Register – Security

Bankrupt scooter startup left one private key to rule them all

16 January 2026 at 12:59

Owner reverse-engineered his ride, revealing authentication was never properly individualized

An Estonian e-scooter owner locked out of his own ride after the manufacturer went bust did what any determined engineer might do. He reverse-engineered it, and claims he ended up discovering the master key that unlocks every scooter the company ever sold.…

Probably not the best security in the world: Carlsberg wristbands spill visitor pics

16 January 2026 at 12:00

Researcher shows how anyone can access Copenhagen experience attendees' names, videos

ExclusiveΒ  The Carlsberg exhibition in Copenhagen offers a bunch of fun activities, like blending your own beer, and the Danish brewer lets you relive those memories by making images available to download after the tour is over.…

Chinese spies used Maduro's capture as a lure to phish US govt agencies

15 January 2026 at 23:15

What's next for Venezuela? Click on the file and see

What policy wonk wouldn't want to click on an attachment promising to unveil US plans for Venezuela? Chinese cyberspies used just such a lure to target US government agencies and policy-related organizations in a phishing campaign that began just days after an American military operation captured Venezuelan President NicolΓ‘s Maduro.…

Flipping one bit leaves AMD CPUs open to VM vuln

15 January 2026 at 22:11

Fix landed in July, but OEM firmware updates are required

If you use virtual machines, there's reason to feel less-than-Zen about AMD's CPUs. Computer scientists affiliated with the CISPA Helmholtz Center for Information Security in Germany have found a vulnerability in AMD CPUs that exposes secrets in its secure virtualization environment.…

Contagious Claude Code bug Anthropic ignored promptly spreads to Cowork

Office workers without AI experience warned to watch for prompt injection attacks - good luck with that

Anthropic's tendency to wave off prompt-injection risks is rearing its head in the company's new Cowork productivity AI, which suffers from a Files API exfiltration attack chain first disclosed last October and acknowledged but not fixed by Anthropic.…

A simple CodeBuild flaw put every AWS environment at risk – and pwned 'the central nervous system of the cloud'

15 January 2026 at 16:00

And it's 'not unique to AWS,' researcher tells The Reg

A critical misconfiguration in AWS's CodeBuild service allowed complete takeover of the cloud provider's own GitHub repositories and put every AWS environment in the world at risk, according to Wiz security researchers.…

US regulator tells GM to hit the brakes on customer tracking

15 January 2026 at 14:30

Smart Driver pitched as safety app, but feds claim it's a data-harvesting scheme that jacked up premiums

The Federal Trade Commission has banned General Motors and subsidiary OnStar from sharing drivers' precise location and behavior data with consumer reporting agencies for five years under a 20-year consent order finalized January 14.…

Received β€” 15 January 2026 ⏭ The Register – Security
Received β€” 14 January 2026 ⏭ The Register – Security
❌