❌

Normal view

Received β€” 24 January 2026 ⏭ The Register – Security

Feds totally skipping infosec industry's biggest conference this year

24 January 2026 at 01:22

But ex-CISA boss and new RSAC CEO Jen Easterly will be there

updatedΒ  The US Cybersecurity and Infrastructure Security Agency won't attend the annual RSA Conference in March, an agency spokesperson confirmed to The Register. Sessions involving speakers from the FBI and National Security Agency (NSA) have also disappeared from the agenda.…

Received β€” 23 January 2026 ⏭ The Register – Security
Received β€” 22 January 2026 ⏭ The Register – Security

Crims compromised energy firms' Microsoft accounts, sent 600 phishing emails

22 January 2026 at 20:18

Logging in, not breaking in

Unknown attackers are abusing Microsoft SharePoint file-sharing services to target multiple energy-sector organizations, harvest user credentials, take over corporate inboxes, and then send hundreds of phishing emails from compromised accounts to contacts inside and outside those organizations.…

Received β€” 21 January 2026 ⏭ The Register – Security

Don't click on the LastPass 'create backup' link - it's a scam

21 January 2026 at 19:10

Phishing campaign tries to reel in master passwords

updatedΒ  Password managers make great targets for attackers because they can hold many of the keys to your kingdom. Now, LastPass has warned customers about phishing emails claiming that action is required ahead of scheduled maintenance and told them not to fall for the scam. …

Received β€” 20 January 2026 ⏭ The Register – Security

Remember VoidLink, the cloud-targeting Linux malware? An AI agent wrote it

20 January 2026 at 19:48

AI + skilled malware developers = security threat

VoidLink, the newly spotted Linux malware that targets victims' clouds with 37 evil plugins, was generated "almost entirely by artificial intelligence" and likely developed by just one person, according to the research team that discovered the do-it-all implant.…

Received β€” 16 January 2026 ⏭ The Register – Security

Chinese spies used Maduro's capture as a lure to phish US govt agencies

15 January 2026 at 23:15

What's next for Venezuela? Click on the file and see

What policy wonk wouldn't want to click on an attachment promising to unveil US plans for Venezuela? Chinese cyberspies used just such a lure to target US government agencies and policy-related organizations in a phishing campaign that began just days after an American military operation captured Venezuelan President NicolΓ‘s Maduro.…

A simple CodeBuild flaw put every AWS environment at risk – and pwned 'the central nervous system of the cloud'

15 January 2026 at 16:00

And it's 'not unique to AWS,' researcher tells The Reg

A critical misconfiguration in AWS's CodeBuild service allowed complete takeover of the cloud provider's own GitHub repositories and put every AWS environment in the world at risk, according to Wiz security researchers.…

Received β€” 14 January 2026 ⏭ The Register – Security

Popular Python libraries used in Hugging Face models subject to poisoned metadata attack

13 January 2026 at 22:17

The open-source libraries were created by Salesforce, Nvidia, and Apple with a Swiss group

Vulnerabilities in popular AI and ML Python libraries used in Hugging Face models with tens of millions of downloads allow remote attackers to hide malicious code in metadata. The code then executes automatically when a file containing the poisoned metadata is loaded.…

Received β€” 13 January 2026 ⏭ The Register – Security
Received β€” 12 January 2026 ⏭ The Register – Security
Received β€” 11 January 2026 ⏭ The Register – Security
❌