The UK's criminal records office, ACRO, has escaped a fine and received a regulatory reprimand after security failings potentially exposed highly sensitive data belonging to nearly 11,000 people. ACRO disclosed the "cybersecurity incident" in April 2023, and said at the time that it had no evidence to suggest that any data was compromised. However, it has now emerged that attackers maintained persistent access to ACRO's website and content management system for more than seven months, and staged sensitive data for possible exfiltration. According to the Information Commissioner's Office (ICO), which reprimanded ACRO rather than imposing a financial penalty, the breach was uncovered in March 2023 only because ACRO was investigating a separate intrusion. The watchdog said that while investigating an SQL injection attack that compromised 15 sets of credentials, most belonging to ACRO staff, investigators found evidence of separate intrusions dating back to July 8, 2021. The incidents fell into three categories, the ICO said. Some did not affect personal data, while others exposed only a small number of account credentials. The most serious involved ACRO's website and its Kentico content management system. The intrusion began on August 5, 2022, and the attackers maintained persistent access, without being detected, until March 14, 2023. The ICO found that ACRO ran version 12.0.0 of Kentico CMS from September 2019 until March 2023 without applying the patches and hotfixes released during that period, leaving known vulnerabilities unresolved. The ICO blamed poor communication between ACRO and its managed service provider. The supplier did not learn that patching was its responsibility until February 2020 and continued to assume that it was not required to monitor actively for security updates. "The ambiguity around who was accountable for identifying necessary Kentico CMS patches created a gap where patches and hotfixes were missed, which ultimately left ACRO's website vulnerable," the ICO said. Further, ACRO did not have a documented policy that covered patching Kentico CMS, nor could it demonstrate how vulnerabilities were identified or prioritized. ACRO's Trend Micro antivirus generated alerts, but nobody appears to have been minding them. The records office told the ICO that, for reasons redacted from the postmortem, it was "unable to establish what business processes existed for the assessment or handling of security alerts at the relevant time." It also could not identify which roles were responsible for reviewing these alerts at the time, ultimately resulting in them going unread. ACRO's poor logging means that, despite an extensive investigation by a third-party cybersecurity outfit, it remains impossible to determine whether the affected data was exfiltrated. Investigators did establish that the attackers staged the data for possible exfiltration between February 15 and 16, 2023. The potentially exposed material included: Police Certificate Applications Subject Access Request (SAR) forms and International Child Protection Certificate forms Names Dates of birth Addresses National Insurance numbers Passport and driving licence details Bank account information Biometric data Highly sensitive criminal offence and special category information ACRO notified 84,048 people of the breach, although investigators later determined that data relating to no more than 10,920 individuals had potentially been staged for exfiltration. Of these, ACRO received 35 formal complaints citing personal distress and concern about the risk of identity theft and financial loss, according to the ICO's reprimand document [PDF]. "Complainants included those connected to Police Certificates, International Child Protection Certificates, and victims of domestic violence." The ICO also received six complaints citing similar concerns. ACRO's saving grace was its network segmentation, which prevented the attackers from straying beyond the CMS into other systems, the ICO noted. Since the attack was discovered, ACRO has made a number of improvements to its security, including decommissioning the compromised infrastructure (although not until June 2023), implementing a SIEM, improving visibility, monitoring, and network segmentation, hardening systems, and migrating to Salesforce Experience Cloud. Jonathan Balmforth, group manager of civil and cyber investigations at the ICO, said: "This case highlights how basic cyber security failings can create significant risks for thousands of people, particularly where organizations process large volumes of highly sensitive personal information. "Organizations must ensure there is clear accountability for identifying, assessing and applying security updates. They must also have effective monitoring in place so that warning signs of cyberattacks are identified, investigated and acted upon promptly. "The lessons from this incident are clear. Having the right policies, responsibilities and oversight arrangements in place is just as important as having the right technology. "We welcome the improvements ACRO has made since these incidents. We hope other organizations will use this case as an opportunity to review their own processes and responses to ensure personal information remains properly protected." ACRO welcomed the reprimand from the ICO and highlighted the steps it has taken since to bolster its security. A spokesperson told The Register: "Since the cybersecurity incident was identified in March 2023, we have worked hard to strengthen our systems and safeguards. "In particular, we immediately took the previous website offline and subsequently decommissioned it. We also took steps to protect customers, including making sure anyone potentially affected was informed at the earliest possible stage." They went on to say: "We accept the ICO's findings of the infringements. We are grateful for the recognition from the Information Commissioner of the multiple remedial steps ACRO has taken in light of this incident and are committed to maintaining high standards of data protection and information security in future." ®
British Transport Police is expanding its trial of live facial recognition (LFR) to the London Underground, despite concerns about privacy and mistaken identification. The force, which polices railways across England, Scotland, and Wales, will begin its Tube deployments at Victoria Underground station. The cameras will then rotate between Underground and Network Rail stations until the trial ends in November. The trial began at London Bridge railway station in February and is intended to assess how the technology performs in a railway setting. It follows deployments by the Metropolitan Police, which says it will start using face-scanning cameras in London's West End and Soho by the end of this year after a six-month pilot in the south London borough of Croydon. Live facial recognition scans faces within a camera's field of view and compares them with a police watchlist. A possible match generates an alert that an officer must review before deciding whether further action is warranted. According to the railway bobbies, the technology deployed relies on the NEC NeoFace M40 algorithm, which appears to be the same across several forces. "Expanding deployments into London Underground stations will help us assess the technology in a different transport environment while continuing to refine how it is used across the railway network," said the officer responsible for the project, chief superintendent Chris Casey. Critics describe the technology as dystopian and intrusive, and errors have already resulted in innocent people being mistaken for criminals and detained. Members of ethnic minorities appear to be more at risk of being mistaken for someone else by facial algorithms. "This is a disturbing and dystopian expansion of live facial recognition that will capture millions of innocent people's faces. Far from reserving this for exceptional cases, British police are now using live facial recognition routinely in the sort of pervasive way you might expect in China, but not in a democracy," says Silkie Carlo, director of civil liberties group Big Brother Watch. The London Underground network is estimated to handle more than 3.7 million passenger journeys a day on weekdays. A recent Opinium survey of 2,000 UK adults, commissioned by facial recognition biz Face Int, found that 69 percent believed the public should have a say in how the technology is used. It also found that 61 percent worried errors could get people into trouble for things they had not done, while 57 percent were concerned about how facial images were stored. Britain's railway fuzz says images of anyone who does not match the authorized watchlist are deleted immediately and permanently. Whether that remains the policy in future is another matter, of course. We asked the British Transport Police to comment regarding public concerns about the use of facial recognition technology. A spokesperson for the force referred to us to the comments made in the announcement by chief superintendent Casey, who said: "Our focus remains on protecting the public, preventing crime and bringing offenders to justice, while ensuring the technology is used lawfully, proportionately and transparently." ®
Signal has introduced a new layer of security to help make sure no one has secretly interfered with your encrypted chats. The chat app is favored by diplomats, activists, and journalists for its security. It uses end-to-end message encryption and “safety numbers” – cryptographic fingerprints associated with the keys securing a conversation – which users can compare to verify they have the expected encrypted connection with a contact. But in theory, someone could still intercept messages by corrupting the centralized directory of accounts and posing as somebody else – a classic "man in the middle" attack. Everything would still be encrypted, just going to the wrong place. To fight this possibility, Signal announced a new feature called Automatic Key Verification (AKV) on Tuesday. From a user perspective, AKV is easy: Tap on a Signal contact’s profile, navigate to the “View Safety Number” screen, and tap on the “Verify automatically” button. It will then show a green checkmark to verify that the contact’s public encryption key matches what Signal’s key transparency system expects. Behind the scenes, however, Signal has developed a new architecture for detecting whether someone has tampered with the public keys associated with an account to intercept messages, as that would require a change to the public encryption key and, in turn, the safety number that a user might not recognize. Ledgers and trees and third parties, oh my! Signal described the new system as serving as a ledger of public keys in which every change a user makes to their information (e.g., linked phone number) leads to a new iteration of the ledger. Accompanying that ledger is an index, allowing Signal users to verify the information in the ledger about themselves or their contacts to make sure it hasn’t been altered by a malicious third party seeking to intercept messages. This ledger lives on an “open-source key transparency server” Signal created for the AKV process, the company said. “When Signal users register, change their phone number or username, or re-create their account, Signal records the changes in a log tree ('the ledger') and facilitates searching through the log tree with prefix trees ('the index books'),” Signal said in the announcement. Digging through an index is hardly automatic, however, so Signal combs the index on the user's behalf to verify the information they’re retrieving about a contact is the most up-to-date. Up-to-date doesn’t mean it’s accurate, however, which is where third-party auditors come in. Cloudflare and security firm Trail of Bits serve as Signal’s AKV third-party auditors, according to the announcement. Their role in the whole thing is to verify that Signal’s own key transparency server isn’t compromised. Per the announcement, third-party auditors check the index to ensure entries don’t appear to have been altered. If those checks come out clear, the auditor signs the response to indicate that the keys being provided are the same for both users, thus eliminating the possibility of a man-in-the-middle attack. Yet again we have a security shortcoming, as auditors can guarantee the index and key transparency server hasn’t been tampered with, but can’t verify the accuracy of the data they contain, which is where the final part of the puzzle comes in: Monitoring. “There are two ways for customers to interact with the ledger: looking up someone else’s address, and looking up their own,” Signal explained. “Monitoring requires Alice and Bob [your usual cryptographic placeholders] to do both of these things on a regular basis, each detecting a different kind of tampering.” Alice and Bob are each able to monitor their own ledger entries via the Signal app, which periodically checks it automatically, and they can verify their connection’s data is correct through the View Safety Number “Verify Automatically” button we mentioned earlier. “These two kinds of monitoring, combined with third-party auditing, form a complete detection system: auditing guarantees that Alice and Bob are looking at the same data, and monitoring guarantees that both of them are regularly checking that data for accuracy,” Signal explained. Security is never simple AKV still ultimately leaves Signal users on the hook for their security: If you want to be truly sure your contact is who they say they are, you’ll need to hit that verify button every time you want to chat. It’s also worth pointing out that this won’t always work for all Signal users. “Your Signal app automatically verifies your own phone number and username data in the log,” the announcement said. “But to verify this for someone else, you need to have their phone number.” In other words, if you don’t have your contact’s phone number through Signal or a matching entry in your phone’s address book, you can’t use AKV to verify the encryption key associated with that contact. AKV can also be disabled for users who don’t want a third party involved in verifying their identity, in which case Signal recommends relying on good old fashioned safety number or QR code verification. Nothing in the cryptographic verification space is ever easy, is it?®
This is an epic month for Microsoft patches, though not a record-setting one. Redmond addressed 421 bugs in its own products this month - about 200 fewer CVEs than last month, but likely the new norm with AI-assisted vulnerability disclosures and fixes. The big news is that North Korea’s Lazarus Group (and possibly other miscreants) found and attacked one of these flaws as a zero-day in early June. The bug, tracked as CVE-2026-68820, is a use-after-free in the Windows Ancillary Function Driver for WinSock. “A locally authenticated attacker could run a specially crafted application on an affected system to trigger a race condition,” Redmond warned, adding that successful exploitation could allow an attacker to execute code with SYSTEM-level privileges, and with no user interaction required. Microsoft credited Check Point researchers Moshe Marelus and David Driker with finding and reporting CVE-2026-68820, and the security shop’s threat intel lead told us that his analysts first observed attackers - namely North Korea’s Lazarus Group - battering this CVE at the beginning of June. “We are familiar with one successful implementation of the CVE - but we assume it was used widely in the campaign,” Sergey Shykevich, director of threat intelligence at Check Point, told The Register. He’s talking about Operation Dream Job, a long-running campaign targeting organizations worldwide, especially those in the defense sector, and attributed to Lazarus, an umbrella term for Pyongyang's government-sponsored goons who specialize in cryptocurrency theft, extortion attacks, and IT worker scams. It’s probably best known for the Sony Pictures Entertainment hack in late 2014 and the WannaCry ransomware outbreak in 2017, although the group has been active since at least 2009. Lazarus’ DreamJob campaigns have been around since 2020, and they use social engineering to lure job seekers with fake offers for high-profile positions, then trick the victims into clicking on malicious links or opening malware-laced documents. The goal in these attacks involves stealing IP and other sensitive data, conducting cyber spying missions, and collecting financial information. When Dream Job and Patch Tuesday collide This new wave of attacks focuses on the defense sector in Europe and India with dream jobs impersonating Lockheed Martin and privacy-tech firm Enveil. Attackers created at least three fake Enveil sites, and some even ranked as the top search result, making them even more believable to job seekers - and harder to spot a phish. “In this campaign, the threat actor expanded its delivery method by leveraging impersonation websites and search engine optimization (SEO) techniques to distribute the trojanized applications, increasing its credibility and helping it evade some phishing-based detections,” Check Point researchers said in a Tuesday blog. These attacks involve Lazarus distributing a modified PDF viewer called SecurityPDF designed to execute malicious payloads embedded within attacker-crafted PDF files when the user opens them. The PDFs, when opened, execute a never-before-seen backdoor that Check Point named Troy. And during the intrusions, the Norks exploited CVE-2026-68820 as a zero-day to deploy a new version of FudModule, Lazarus’ kernel-mode rootkit. “We will not be disclosing full technical details of the vulnerability in this article, as it was patched on the August 11 Patch Tuesday fix,” the researchers wrote. “At a high level, the exploit takes advantage of how afd.sys handles a socket is created when it is accessed concurrently by several threads at once.” Shykevich told us that “this campaign shows that this actor continues to develop new tools (like Troy), and finding and implementing new vulnerabilities in Windows to evade detection.” Best of the rest Redmond lists one of the other 421 Microsoft CVEs as publicly known. It’s CVE-2026-62832, an elevation-of-privilege flaw, and the Windows giant says exploitation is “more likely,” so patch this one sooner. “An authenticated attacker who has credentials for another local account could run a specially crafted application to load another user's registry hive,” according to the security advisory. “Successful exploitation could allow the attacker to access or modify another user's data and gain administrator privileges. User interaction is not required.” While CVE-2026-68820 and CVE-2026-62832 are the only vulnerabilities that Microsoft considers “notable” in its August patch cycle, Trend Micro’s Zero Day Initiative highlights five others, including one that came through ZDI’s bug reporting program and another that was successfully exploited at ZDI’s Pwn2Own contest in Berlin. All five of these should be considered notable and exploitable, so give those a read, too. CVE-2026-62893, a critical flaw in Windows Deployment Services TFTP Server that leads to remote code execution without user authentication or user interaction, is the one disclosed through ZDI. “TFTP has no auth mechanism and is available remotely vid UDP port 69,” ZDI bug boss Dustin Childs wrote. “UDP port 69 should be blocked at your perimeter, but this could easily be used by attackers for lateral movement within an enterprise. Again, test and deploy this one quickly if you’re using WDS for deployments in your enterprise.” Meanwhile, CVE-2026-62911, one of the many Exchange bugs in this month’s release, was demonstrated at ZDI’s Pwn2Own in Berlin. It allows a privilege escalation via an authentication bypass, and exploitation would allow an attacker to “take over the mailboxes of all Exchange users, attackers can send emails, read emails, download attachments,” according to Microsoft, which oddly deemed “exploitation less likely.” Childs calls BS on this. “Ignore Microsoft’s exploitability and Exploit Code Maturity ratings,” he wrote. “We handed them working exploits, so this is a real threat.” ®
A passenger on a Delta Air Lines flight from Las Vegas to Atlanta after DEF CON is suspected of jamming the in-flight Wi-Fi and broadcasting an unauthorized network in what could amount to a federal offense. It seems like someone forgot the old truism "what happens in Vegas stays in Vegas." News of the incident began circulating late Monday when flight watchers spotted Aircraft Communications Addressing and Reporting System (ACARS) messages from the crew of Delta Flight 591 indicating that something was up with the Wi-Fi and that they suspected a passenger was to blame. “HEY ALERT CORP SECURITY WE HAVE A PAX [passenger] ON THAT HAS CREATED A SCAM WIFI CALLED DELTA WIFI FAST WE BELIEVE THEY ARE TRYING TO SCAM THE OTH PAX,” the first notice read. Several minutes later, the flight crew followed up with a second message stating they had little additional info at the time, but pointing the blame at “A BUNCH OF PAX THAT WERE AT A CYBER CONFERENCE IN LAS” who “WERE ABLE TO JAM OUR WIFI” and broadcast their own signal. From there, the timeline and truth of the situation get a bit fuzzy, with accounts on social media differing as to what happened next. A poster on X speculated that the culprit was trying to phish for passenger credentials by setting up the fake Wi-Fi network, while a Facebook post shared to Reddit claimed that the incident involved a deauthentication attack that kicked users off the legitimate network before bringing up their own, which included a fake landing page, possibly using a device like a Wi-Fi Pineapple, which can broadcast fake networks, perform deauth attacks, and the like. A commenter in a thread on the Hacking subreddit (linked above) claimed to have been at the terminal in Las Vegas and said the individual was doing the same thing to airport Wi-Fi. The Facebook and X posts both claimed that law enforcement was waiting at the gate, though a post in the Delta subreddit included a comment from someone claiming to have been on the flight who didn’t see any police waiting at the gate. Regardless of what actually transpired once the plane landed, Delta Air Lines confirmed the incident to The Register. “We are fully investigating to gather a complete set of facts, which will take time,” a Delta spokesperson told us in an email. “We will partner with federal law enforcement and aviation regulators to ensure the incident is thoroughly investigated.” Delta further noted that the safety of the plane, crew, and passengers was never in question, and no aircraft systems were affected. The airline also told us that there was no hack of any Delta system, including the in-flight Wi-Fi, though it did confirm that an unauthorized Wi-Fi network was broadcast onboard the aircraft for a short period of time. Some of the confusion over the possible deauthentication attack may have come from the cabin crew deactivating the in-flight Wi-Fi for around 30 minutes due to the incident, Delta explained. The airline reiterated that the flight was leaving following the wrap-up of Black Hat and DEF CON, suggesting it suspected an attendee was behind the bad decision. We asked the Atlanta Police’s airport division if it was involved at all, and a representative told us they were unaware of the incident. Atlanta’s Department of Aviation declined to provide any comment on the matter. Based on Delta’s comment, it’s not clear whether the incident involved deliberate interference with authorized Wi-Fi communications, but if investigators determine that it did, the penalties could be severe. According [PDF] to the Federal Communications Commission, intentional Wi-Fi blocking can violate the Communications Act’s section 333. A willful and knowing violation punishable under the Act’s general criminal provision could carry a penalty of up to one year in prison and/or a fine of up to $10,000 upon conviction. If this wannabe hacker with a penchant for choosing the worst possible target in the world is stupid enough to have been caught doing this before (and let’s be frank - if you’re going to try jamming the Wi-Fi on a commercial airplane, you’re not that bright), that prison term could extend to up to two years. ®
Ongoing wars in Ukraine and Iran and the FIFA World Cup all contributed to a DDoS walloping of media organizations throughout 2026 so far, according to Cloudflare’s latest data, which identified the sector as the most targeted this year. Attacks on media, production, and publishing accounted for 14.2 percent of all DDoS attacks launched since January 1. Over the first six months of the year, the sector saw nearly four times the number of attacks leveled at the second most-targeted sector, gambling and casinos, and six times more in Q2 alone. “DDoS attacks on media organisations can be highly effective at achieving their core goals, which differ fundamentally from attacks on other sectors," Blake Darché, Head of Cloudforce One and Threat Intelligence at Cloudflare, told The Register. "For publishers, availability is the deliverable. While a DDoS attack on an e-commerce site could aim to steal transaction revenue, an attack on a publisher is typically aimed at censorship, information suppression or timing disruption. “DDoS attacks are uniquely effective against publishers because news expires quickly - taking an outlet offline for just two hours during an election night, a military conflict, or a breaking news story successfully silences it at peak readership. The attack succeeds even if systems recover shortly after.” Cloudflare's data aligns with third-party reporting shortly after the US started a war with Iran in February. Akamai reported a 245 percent uplift in cybercrime in the immediate weeks following the war breaking out, with DDoS attacks up 38 percent. Similarly, Justin Moore, senior manager at Palo Alto Networks' Unit 42, previously told The Register that by the start of March, the company’s telemetry showed a clear increase in pro-Russia hacktivism too. Hacktivists rely heavily on DDoS attacks to carry out their objectives. Often assembled on social media platforms, hacktivist groups decide on which organizations they will attempt to down and launch coordinated attacks against them. Signals intelligence agencies say these efforts are almost always low-level and low-impact, but equally advise that businesses should not underestimate these groups. The advice applies largely to operators of critical infrastructure, which if attacked successfully and for a sustained period, could lead to vital service disruption. The US’ war in Iran also led to a major uptick in attacks targeting government entities. From the 29th most-targeted sector in Q1, it jumped to number nine in Q2. The US and China comprised the two most-targeted regions, although Turkey shot up to third after it hosted the Ankara NATO summit in July. 1 Tbps network-layer attacks explode Cloudflare said it mitigated 805 network-layer attacks exceeding 1 Tbps in Q2 alone, representing a 519 percent increase compared to Q1. To quickly debunk some jargon for the uninitiated, network-layer attacks are confined to layer 3 of the Open Systems Interconnection (OSI) model, meaning that they target core routing, transport, and infrastructure protocols to overwhelm networking equipment. Not all 1 Tbps+ attacks target the network layer. These high-packet onslaughts are referred to as hyper-volumetric DDoS attacks and involve transmitting a huge amount of data to a network – enough to take down even the most robust internet infrastructure. Despite the growth in these hyper-volumetric attacks, these comprise only the smallest fraction of DDoS attacks overall (0.004 percent). The vast majority – 96.62 percent – transmit less than 500 Mbps and 90.6 percent end in under ten minutes. That isn’t to say that these attacks are inconsequential, either. Cloudflare said that even attacks of this size would be enough to knock most networks offline. Putting it into perspective, the company said a 100 Mbps attack would be sufficient to knock a website or server offline, while a 1 Gbps attack could disrupt an entire datacenter if it wasn’t protected from DDoS attacks. 1 Tbps hyper-volumetric attacks are among the fastest ever observed. The first of this kind on record targeted Dyn DNS in 2016, in turn downing major websites such as Twitter, Netflix, Reddit, Spotify, and GitHub, and they have become increasingly common since then, despite their markedly low proportion compared to other DDoS attacks. A law enforcement operation in March disrupted the infrastructure relied upon by four of the most significant botnets operating at the time, including Aisuru, which by the end of 2025 had recruited up to 4 million devices and was rattling out multiple 1 Tbps attacks daily. Hyper-volumetric attacks are often short-lived, measured in seconds rather than greater units, although Cloudflare said even this is enough to cause significant damage. “Whether an attack lasts half a minute or ten minutes, there is no practical window for human intervention: By the time an alert reaches a security analyst, the attack has already completed,” said Cloudflare in its report. “Manual mitigation and on-demand solutions are simply too slow for this reality. Yet while the attack itself may be brief, its aftershocks are not. The cascading effects of even a short burst can trigger routing instability, TCP retransmissions, application timeouts, and downstream service degradation that takes hours or days to fully resolve – all while services remain down or impaired.” ®