❌

Normal view

Received β€” 26 January 2026 ⏭ The Register – Security

Pwn2Own Automotive 2026 uncovers 76 zero-days, pays out more than $1M

Also, cybercriminals get breached, Gemini spills the calendar beans, and more

infosec in briefΒ  T'was a dark few days for automotive software systems last week, as the third annual Pwn2Own Automotive competition uncovered 76 unique zero-day vulnerabilities in targets ranging from Tesla infotainment to EV chargers.…

Received β€” 19 January 2026 ⏭ The Register – Security

CrowdStrike shareholders lose battle to recoup losses from 2024 outage

Investors didn't present a valid claim, says judge, but they're welcome to try again

A group of CrowdStrike shareholders who sued the company over losses sustained following its 2024 global outage will have to head back to the drawing board if they hope to recoup losses, as a Texas judge has deemed they failed to adequately state a claim.…

Mandiant releases quick credential cracker, to hasten the death of a bad protocol

PLUS: Navy spy sent to brig for 200 months; Black Axe busted again; Bill aims to crimp ICE apps; and more

Infosec In BriefΒ  PLUS: Google’s security outfit Mandiant last week released tools that can crack credentials in 12 hours, in the hope that doing so will accelerate the death of an ancient Microsoft security protocol.…

Received β€” 16 January 2026 ⏭ The Register – Security

Contagious Claude Code bug Anthropic ignored promptly spreads to Cowork

Office workers without AI experience warned to watch for prompt injection attacks - good luck with that

Anthropic's tendency to wave off prompt-injection risks is rearing its head in the company's new Cowork productivity AI, which suffers from a Files API exfiltration attack chain first disclosed last October and acknowledged but not fixed by Anthropic.…

Received β€” 12 January 2026 ⏭ The Register – Security
Received β€” 11 January 2026 ⏭ The Register – Security

Stalkerware slinger pleads guilty for selling snooper software to suspicious spouses

pcTattletale boss Bryan Fleming faces up to 15 years in prison when sentenced later this year

The US government has secured a guilty plea from a stalkerware maker in federal court, marking just the second time in more than a decade that the US has managed to prosecute a consumer spyware vendor successfully. …

Trump admin sends heart emoji to commercial spyware makers with lifted Predator sanctions

Also, Korean Air hacked, EmEditor installer hijacked, a perfect 10 router RCE vuln, and more

infosec in briefΒ  The Trump administration has cleared a trio of individuals sanctioned by the Biden administration for involvement with the Intellexa spyware consortium behind the Predator surveillance tool, removing restrictions that had barred them from doing business with the US.…

European Space Agency hit again as cybercrims claim 200 GB data up for sale

31 December 2025 at 17:55

As in past incidents, ESA says the impact was limited to external systems

The European Space Agency has suffered yet another security incident and, in keeping with past practice, says the impact is limited. Meanwhile, miscreants boast that they've made off with a trove of data, including what they claim are confidential documents, credentials, and source code.…

An early end to the holidays: 'Heartbleed of MongoDB' is now under active exploit

30 December 2025 at 20:27

You didn't think you'd get to enjoy your time off without a major cybersecurity incident, did you?

A high-severity MongoDB Server vulnerability, for which proofs of concept emerged over Christmas week, is now under active exploitation, according to the US Cybersecurity and Infrastructure Security Agency.…

❌