❌

Normal view

Received today β€” 4 April 2026 ⏭ The Register - Security

Hybrid work, expanded risk: what needs to change

3 April 2026 at 16:00

A practical look at securing identities, devices and applications wherever work happens

Webinar Promo The shift to hybrid work has reshaped the enterprise perimeter. Users are logging in from home networks, shared spaces and unmanaged devices, while applications span on-prem systems and multiple clouds. Traditional security models were not designed for this level of fragmentation, leaving many organizations struggling to maintain visibility and control without adding friction.…

Received β€” 2 April 2026 ⏭ The Register - Security

The company's biggest security hole lived in the breakroom

2 April 2026 at 08:01

Connected devices can leave an otherwise secure network vulnerable

Pwned Welcome to Pwned, The Register's new column, where we highlight the worst infosec own goals so you can, hopefully, protect against them. Caffeine is an essential tool for most IT defenders, so, on balance, we're sure it has protected against a lot more exploits than it has caused. But in this case, the desire for everyone's favorite stimulant led to a massive breach.…

Received β€” 1 April 2026 ⏭ The Register - Security

Don't open that WhatsApp message, Microsoft warns

31 March 2026 at 21:18

How to avoid social engineering attacks? Employee training tops the list

Be careful what you click on. Miscreants are abusing WhatsApp messages in a multi-stage attack that delivers malicious Microsoft Installer (MSI) packages, allowing criminals to control victims' machines and access all of their data.…

Iran targets M365 accounts with password-spraying attacks

31 March 2026 at 19:09

Researchers say some targets correlate with cities hit by Iranian missile strikes

Suspected Iran-linked threat actors are conducting password-spraying attacks against hundreds of organizations, primarily Middle Eastern municipalities, in campaigns that security researchers believe may have been aimed at supporting bomb-damage assessment following missile strikes.…

Received β€” 31 March 2026 ⏭ The Register - Security

Supply chain blast: Top npm package backdoored to drop dirty RAT on dev machines

31 March 2026 at 10:29

Hijacked maintainer account let attackers slip cross-platform trojan into 100M-downloads-a-week Axios

Updated One of npm's most widely used HTTP client libraries briefly became a malware delivery vehicle after attackers hijacked a maintainer's account and slipped a remote-access trojan (RAT) into two seemingly legitimate axios releases, in what's being described as "one of the most impactful npm supply chain attacks on record."…

Received β€” 30 March 2026 ⏭ The Register - Security

Security contractor blew the whistle on support crew's viral indifference

30 March 2026 at 07:30

Career-limiting stupidity and rudeness exposed, with terminal consequences

Who, Me? The week before Easter may be a short one for many in the Reg-reading world, but that won't stop us from opening it with a fresh installment of Who, Me? It's the reader-contributed column in which you share stories of things you did at work that had interesting consequences.…

US foreign router ban criticized for being β€˜industrial policy disguised as cybersecurity’

30 March 2026 at 04:31

Public policy professor says it will make America less secure but hits Netgear’s lobbying goals

The United States’ ban on foreign-made SOHO routers won’t improve security, and only makes sense as β€œindustrial policy disguised as cybersecurity,” according to Milton Mueller, Professor at the University of Georgia’s School of Public Policy and founder of its Internet Governance Project.…

Received β€” 27 March 2026 ⏭ The Register - Security

AFC Ajax drops ball as flaws let hackers play admin with tickets and bans

27 March 2026 at 12:30

Vulns in Dutch football club's systems didn't just expose data – they let outsiders play with accounts, and even lift stadium bans

Dutch football giant AFC Ajax has admitted to a data breach after an attacker gained access to its internal systems, in an incident that looks less like a stray pass and more like the gates left wide open.…

❌