❌

Normal view

Critical Microsoft Excel bug weaponizes Copilot Agent for zero-click information disclosure attack

10 March 2026 at 21:35

Could steal sensitive personal and financial data

After a whopper of a Patch Tuesday last month, with six Microsoft flaws exploited as zero-days, March didn't exactly roar in like a lion. Just two of the 83 Microsoft CVEs released on Tuesday are listed as publicly known, and none is under active exploitation, which we're sure is a welcome change to sysadmins.…

Cybercrime isn't just a cover for Iran's government goons - it's a key part of their operations

10 March 2026 at 19:25

Ransomware, malware-as-a-service, infostealers benefit MOIS, too

Iranian government-backed snoops are increasingly using cybercrime malware and ransomware infrastructure in their operations - not just hiding behind criminal masks as a cover for destructive cyber activity, according to security researchers.…

AI agents now help attackers, including North Korea, manage their drudge work

8 March 2026 at 12:00

Crims 'will do what gets them their objective easiest and fastest,' Microsoft threat intel boss tells The Reg

interviewΒ  AI agents allow cybercriminals and nation-state hackers to outsource the "janitorial-type work" needed to plan and carry out cyberattacks, according to Sherrod DeGrippo, Microsoft's GM of global threat intelligence. North Korea is taking advantage.…

Iran intelligence backdoored US bank, airport, software outfit networks

5 March 2026 at 19:53

MOIS-linked MuddyWater crew has a new, custom implant

An Iranian cyber crew believed to be part of the Iranian Ministry of Intelligence and Security (MOIS) has been embedded in multiple US companies' networks - including a bank, software firm, and airport, among others - since the beginning of February, with more activity in the days following the US and Israeli military strikes, according to security researchers.…

'Hundreds' of Iranian hacking attempts have hit surveillance cameras since the missile strikes

5 March 2026 at 00:59

Attack infrastructure attributed to 'several Iran-nexus threat actors'

Multiple Iranian hacking crews have been targeting internet-connected surveillance cameras across Israel and other Middle Eastern countries since the war started on February 28, according to Check Point security researchers. …

Malware-laced OpenClaw installers get Bing AI search boost

4 March 2026 at 21:50

Think before you download

OpenClaw, the AI agent that can manage just about anything, is risky all by itself, but now fake installers for it are wreaking havoc. Users who searched Bing’s AI results for β€œOpenClaw Windows” were directed to a malicious GitHub repository that delivered information stealers and GhostSocks onto their machines.…

Adidas investigates third-party data breach after criminals claim they pwned the sportswear giant

19 February 2026 at 00:57

'Potential data protection incident' at an 'independent licensing partner,' we're told

Adidas has confirmed it is investigating a third-party breach at one of its partner companies after digital thieves claimed they stole information and technical data from the German sportswear giant.…

China-linked snoops have been exploiting Dell 0-day since mid-2024, using 'ghost NICs' to avoid detection

18 February 2026 at 01:05

Full scale of infections remains 'unknown'

China-linked attackers exploited a maximum-severity hardcoded-credential bug in Dell RecoverPoint for Virtual Machines as a zero-day since at least mid-2024. It's all part of a long-running effort to backdoor infected machines for long-term access, according to Google's Mandiant incident response team.…

China remains embedded in US energy networks 'for the purpose of taking it down'

17 February 2026 at 22:45

Plus 3 new goon squads targeted critical infrastructure last year

Three new threat groups began targeting critical infrastructure last year, while a well-known Beijing-backed crew - Volt Typhoon - continued to compromise cellular gateways and routers, and then break into US electric, oil, and gas companies in 2025, according to Dragos' annual threat report published on Tuesday.…

❌