❌

Normal view

Received β€” 19 January 2026 ⏭ The Register – Security
Received β€” 17 January 2026 ⏭ The Register – Security

Fast Pair, loose security: Bluetooth accessories open to silent hijack

17 January 2026 at 13:26

Sloppy implementation of Google spec leaves 'hundreds of millions' of devices vulnerable

Hundreds of millions of wireless earbuds, headphones, and speakers are vulnerable to silent hijacking due to a flaw in Google's Fast Pair system that allows attackers to seize control without the owner ever touching the pairing button.…

Sorry Dave, I’m afraid I can’t do that! PCs refuse to shut down after Microsoft patch

16 January 2026 at 17:44

Microsoft claims it's a Secure Launch bug

We're not saying Copilot has become sentient and decided it doesn't want to lose consciousness. But if it did, it would create Microsoft's January Patch Tuesday update, which has made it so that some PCs flat-out refuse to shut down or hibernate, no matter how many times you try.…

Received β€” 16 January 2026 ⏭ The Register – Security

Bankrupt scooter startup left one private key to rule them all

16 January 2026 at 12:59

Owner reverse-engineered his ride, revealing authentication was never properly individualized

An Estonian e-scooter owner locked out of his own ride after the manufacturer went bust did what any determined engineer might do. He reverse-engineered it, and claims he ended up discovering the master key that unlocks every scooter the company ever sold.…

US regulator tells GM to hit the brakes on customer tracking

15 January 2026 at 14:30

Smart Driver pitched as safety app, but feds claim it's a data-harvesting scheme that jacked up premiums

The Federal Trade Commission has banned General Motors and subsidiary OnStar from sharing drivers' precise location and behavior data with consumer reporting agencies for five years under a 20-year consent order finalized January 14.…

Received β€” 14 January 2026 ⏭ The Register – Security
Received β€” 13 January 2026 ⏭ The Register – Security

Federal agencies told to fix or ditch Gogs as exploited zero-day lands on CISA hit list

13 January 2026 at 14:04

Git server flaw that attackers have been abusing for months has now caught the attention of US cyber cops

CISA has ordered federal agencies to stop using Gogs or lock it down immediately after a high-severity vulnerability in the self-hosted Git service was added to its Known Exploited Vulnerabilities (KEV) catalog.…

Court tosses appeal by hacker who opened port to coke smugglers with malware

13 January 2026 at 13:10

Dutchman fails to convince judges his trial was unfair because cops read his encrypted chats

A Dutch appeals court has kept a seven-year prison sentence in place for a man who hacked port IT systems with malware-stuffed USB sticks to help cocaine smugglers move containers, brushing off claims that police shouldn't have been reading his encrypted chats.…

Received β€” 12 January 2026 ⏭ The Register – Security
Received β€” 11 January 2026 ⏭ The Register – Security

QR codes a powerful new phishing weapon in hands of Pyongyang cyberspies

9 January 2026 at 16:44

State-backed attackers are using QR codes to slip past enterprise security and help themselves to cloud logins, the FBI says

North Korean government hackers are turning QR codes into credential-stealing weapons, the FBI has warned, as Pyongyang's spies find new ways to duck enterprise security and help themselves to cloud logins.…

❌