The Register - Anti-Virus

Syndikovat obsah
Biting the hand that feeds IT — Enterprise Technology News and Analysis
Aktualizace: 9 min 11 sek zpět

Bug of the year (so far): Nasty cPanel vulnerability probably exploited as a 0-day

55 min 44 sek zpět
Emergency patches out now for those managing the millions of domains assumed to be affected

Emergency patches are available for a critical vulnerability in cPanel and WHM that allows attackers to bypass authentication and gain root access to servers managed using it.…

Kategorie: Viry a Červi

Britain's £6B armoured sickener Ajax cleared for duty despite injuring troops

2 hodiny 24 min zpět
Investigation finds no single cause for soldiers falling ill, just bad bolts, cold air, and apparently the soldiers themselves

Britain's notorious Ajax armored vehicles are being accepted back from the manufacturer after investigations found no single cause for the symptoms plaguing crews, meaning soldiers will need to grin and bear it.…

Kategorie: Viry a Červi

Finance company stores DB credentials in helpfully labeled spreadsheet

3 hodiny 9 min zpět
Great idea, guys. Let's keep all of the data in an Excel file with weak password protection

PWNED  Welcome, once again, to PWNED, the weekly column where we recount the adventures of IT explorers who found their own pile of quicksand and then jumped right into it. This week's story involves keeping sensitive information in a very vulnerable place and then not protecting it adequately.…

Kategorie: Viry a Červi

Linux cryptographic code flaw offers fast route to root

11 hodin 8 min zpět
Patches land for authencesn flaw enabling local privilege escalation

Developers of major Linux distributions have begun shipping patches to address a local privilege escalation (LPE) vulnerability arising from a logic flaw.…

Kategorie: Viry a Červi

Researchers move in the right direction, develop powerful GPS interference alarm

29 Duben, 2026 - 22:11
ORNL says portable detector kit can separate real GPS signals from fake ones even at equal strength

GPS spoofing, which sends fake satellite-like signals, and GPS jamming, which drowns receivers in noise, are increasingly serious problems. Researchers at Oak Ridge National Laboratory in Tennessee have created what they say is the most effective system yet for detecting GPS interference, which could help blunt such attacks.…

Kategorie: Viry a Červi

Microsoft's patch for a 0-day exploited by Russian spies fell short. Another Windows flaw is under attack

29 Duben, 2026 - 21:15
Second try's a charm?

Microsoft and the US Cybersecurity and Infrastructure Security Agency (CISA) warned that attackers are exploiting a zero-click Windows flaw that can expose sensitive information on vulnerable systems.…

Kategorie: Viry a Červi

Legacy TLS tour continues with Exchange Online blocking old versions from July 2026

29 Duben, 2026 - 20:35
Microsoft readies the axe once again for yesterday's security

Microsoft has warned users still clinging to legacy TLS versions that the end is nigh for TLS 1.0 and 1.1 on POP3 and IMAP4 connections to Exchange Online.…

Kategorie: Viry a Červi

CISA flags data-theft bug in NSA-built OT networking tool

29 Duben, 2026 - 17:35
GrassMarlin leaks sensitive information, provided your targeting phishing skills are sharp enough

The Cybersecurity and Infrastructure Security Agency (CISA) is warning anyone who uses GrassMarlin, a tool developed by the National Security Agency (NSA), about a new vulnerability that attackers can use to snoop on sensitive information.…

Kategorie: Viry a Červi

GitHub: Zounds, a genuinely helpful AI-assisted bug report that isn't total slop! Here, Wiz, take this wad of cash

29 Duben, 2026 - 15:02
Claude ploughs through months of work in rapid time, helps Wiz researchers nab lucrative award

Wiz researchers are set for a tidy payday thanks to their discovery of a high-severity flaw in GitHub's git infrastructure that handed remote attackers full read/write access to private GitHub repositories using a single command.…

Kategorie: Viry a Červi

EU waves through open source age-check tool to keep kids safe online

29 Duben, 2026 - 14:03
'Online platforms can rely on our app,' says Commish, 'there are no more excuses'

The European Commission has recommended EU member states adopt an age verification app designed to protect children from harmful online content.…

Kategorie: Viry a Červi

GoDaddy customer claims registrar transferred 27-year-old domain without any security checks

29 Duben, 2026 - 12:00
32 phone calls, 17 email chains, a 5-day ordeal, and no help during the daddy of all stuffups, claim those affected

GoDaddy is currently investigating claims that it handed complete control of a valid 27-year-old domain to another customer, without requiring them to pass any authentication processes or upload any supporting documents.…

Kategorie: Viry a Červi

30 ClawHub skills secretly turn AI agents into a crypto swarm

29 Duben, 2026 - 08:32
Yet another reason not to feast on OpenClaw

Thirty ClawHub skills published by a single author are silently co-opting AI agents and creating a mass cryptocurrency mining swarm – without any malware or user consent.…

Kategorie: Viry a Červi

Don't pay Vect a ransom - your data's likely already wiped out

28 Duben, 2026 - 20:36
'Full recovery is impossible for anyone, including the attacker'

Organizations hit by the wave of Trivy and LiteLLM supply-chain compromises that paid Vect in hopes of recovering their data likely did not get much back, according to Check Point Research. That's because the ransomware Vect uses isn't actually ransomware at all, but a wiper that destroys any file larger than 128KB.…

Kategorie: Viry a Červi

Have I Been Pwned claims Pitney Bowes hit by 8.2M email address leak

28 Duben, 2026 - 16:15
Names, phone numbers, physical addresses also included in Shiny Hunters alleged data dump

Updated  Logistics technology company Pitney Bowes, which makes franking machines for US postage, is the latest scalp claimed by ShinyHunters and its ongoing spree of pay-or-leak attacks against major organizations.…

Kategorie: Viry a Červi

SUSE's sovereignty pitch meets an inconvenient $6 billion question

28 Duben, 2026 - 12:00
Linux vendor touts European independence at SUSECON as majority stakeholder quietly explores its options

European-based SUSE devoted much of the annual SUSECON event to its sovereignty-focused pitch - even as reports swirl that its majority stakeholder is exploring a $6 billion sale which could land the Linux vendor in American hands.…

Kategorie: Viry a Červi

Ongoing supply-chain attack 'explicitly targeting' security, dev tools

28 Duben, 2026 - 01:33
Vendor confirms repo data exposure after Lapsus$ claims source code, secrets dump

Software security testing outfit Checkmarx has become the latest organization caught up in an ongoing attack on security-tool providers. The biz said data posted online appears to have come from one of its GitHub repositories after the Lapsus$ extortion crew claimed to have dumped the company’s source code, secrets, and other sensitive data.…

Kategorie: Viry a Červi

Medical and utility tech companies admit digital breakins

27 Duben, 2026 - 19:53
Itron, Medtronic disclose breaches in Friday filings

Digital intruders recently broke into two major tech suppliers - utility-technology firm Itron and medical-device maker Medtronic - according to filings with federal regulators.…

Kategorie: Viry a Červi

Trump's Golden Dome gets $3.2B of contractors and an AI sprinkle

27 Duben, 2026 - 15:03
Space Force awards 11 firms prototype deals to build orbital interceptors

The United States Space Force (USSF) has awarded eleven companies contracts to develop space-based interceptors for President Trump's Golden Dome program, in agreements worth up to $3.2 billion.…

Kategorie: Viry a Červi

Cybersec is a thankless job: expanding workload and shrinking pay packet

27 Duben, 2026 - 14:22
Global recruitment giant says 71% of human firewalls saw wages stagnate last year as threats and responsibilities grew

Cybersecurity professionals were the most overlooked workers in IT when it came to pay rises in 2025, according to new figures from recruiter Harvey Nash.…

Kategorie: Viry a Červi

Burglar alarm biz burgled: ADT confirms cyber intrusion after ShinyHunters extortion attempt

27 Duben, 2026 - 13:34
Security giant says attackers grabbed 'limited set' of data. Crooks claim 10 million records

A home security biz getting digitally burgled is not a great look - but that's exactly where ADT finds itself. The company has confirmed a cyber intrusion following an extortion attempt by the ShinyHunters crew, which claims to have made off with more than 10 million records.…

Kategorie: Viry a Červi