❌

Normal view

Received β€” 2 February 2026 ⏭ The Register – Security

McDonald's is not lovin' your bigmac, happymeal, and mcnuggets passwords

Your favorite menu item might be easy to remember but it will not secure your account

Change Your Password Day took place over the weekend, and in case you doubt the need to improve this most basic element of cybersecurity hygiene, even McDonald's – yes, the fast food chain – is urging people to get more creative when it comes to passwords. …

Open-source AI is a global security nightmare waiting to happen, say researchers

Also, South Korea gets a pentesting F, US Treasury says bye bye to BAH, North Korean hackers evolve, and more

Infosec in BriefΒ  As if AI weren't enough of a security concern, now researchers have discovered that open-source AI deployments may be an even bigger problem than those from commercial providers. …

Received β€” 28 January 2026 ⏭ The Register – Security

Paranoid WhatsApp users rejoice: Encrypted app gets one-click privacy toggle

Meta also replaces a legacy C++ media-handling security library with Rust

Users of Meta's WhatsApp messenger looking to simplify the process of protecting themselves are in luck, as the company is rolling out a new feature that combines multiple security settings under a single, toggleable option. …

Received β€” 26 January 2026 ⏭ The Register – Security

Pwn2Own Automotive 2026 uncovers 76 zero-days, pays out more than $1M

Also, cybercriminals get breached, Gemini spills the calendar beans, and more

infosec in briefΒ  T'was a dark few days for automotive software systems last week, as the third annual Pwn2Own Automotive competition uncovered 76 unique zero-day vulnerabilities in targets ranging from Tesla infotainment to EV chargers.…

Received β€” 19 January 2026 ⏭ The Register – Security

CrowdStrike shareholders lose battle to recoup losses from 2024 outage

Investors didn't present a valid claim, says judge, but they're welcome to try again

A group of CrowdStrike shareholders who sued the company over losses sustained following its 2024 global outage will have to head back to the drawing board if they hope to recoup losses, as a Texas judge has deemed they failed to adequately state a claim.…

Mandiant releases quick credential cracker, to hasten the death of a bad protocol

PLUS: Navy spy sent to brig for 200 months; Black Axe busted again; Bill aims to crimp ICE apps; and more

Infosec In BriefΒ  PLUS: Google’s security outfit Mandiant last week released tools that can crack credentials in 12 hours, in the hope that doing so will accelerate the death of an ancient Microsoft security protocol.…

Received β€” 16 January 2026 ⏭ The Register – Security

Contagious Claude Code bug Anthropic ignored promptly spreads to Cowork

Office workers without AI experience warned to watch for prompt injection attacks - good luck with that

Anthropic's tendency to wave off prompt-injection risks is rearing its head in the company's new Cowork productivity AI, which suffers from a Files API exfiltration attack chain first disclosed last October and acknowledged but not fixed by Anthropic.…

Received β€” 12 January 2026 ⏭ The Register – Security
Received β€” 11 January 2026 ⏭ The Register – Security

Stalkerware slinger pleads guilty for selling snooper software to suspicious spouses

pcTattletale boss Bryan Fleming faces up to 15 years in prison when sentenced later this year

The US government has secured a guilty plea from a stalkerware maker in federal court, marking just the second time in more than a decade that the US has managed to prosecute a consumer spyware vendor successfully. …

Trump admin sends heart emoji to commercial spyware makers with lifted Predator sanctions

Also, Korean Air hacked, EmEditor installer hijacked, a perfect 10 router RCE vuln, and more

infosec in briefΒ  The Trump administration has cleared a trio of individuals sanctioned by the Biden administration for involvement with the Intellexa spyware consortium behind the Predator surveillance tool, removing restrictions that had barred them from doing business with the US.…

European Space Agency hit again as cybercrims claim 200 GB data up for sale

31 December 2025 at 17:55

As in past incidents, ESA says the impact was limited to external systems

The European Space Agency has suffered yet another security incident and, in keeping with past practice, says the impact is limited. Meanwhile, miscreants boast that they've made off with a trove of data, including what they claim are confidential documents, credentials, and source code.…

An early end to the holidays: 'Heartbleed of MongoDB' is now under active exploit

30 December 2025 at 20:27

You didn't think you'd get to enjoy your time off without a major cybersecurity incident, did you?

A high-severity MongoDB Server vulnerability, for which proofs of concept emerged over Christmas week, is now under active exploitation, according to the US Cybersecurity and Infrastructure Security Agency.…

❌