The Register – Security Biting the hand that feeds IT — Enterprise Technology News and Analysis
- China turns on a vast experimental network it says is an heir to ARPANETby Simon Sharwood on December 19, 2025 at 2:59 am
Beijing wants to ‘seize the initiative in the international competition in cyberspace’ Chinese authorities on Thursday certified the China Environment for Network Innovation (CENI), a vast research network that Beijing hopes will propel the country to the forefront of networking research.…
- Amazon blocked 1,800 suspected North Korean scammers seeking jobsby Jessica Lyons on December 18, 2025 at 11:39 pm
Plus: Lazarus Group has a brand new BeaverTail Even Amazon isn’t immune to North Korean scammers who try to score remote jobs at tech companies so they can funnel their wages to Kim Jong Un’s coffers.…
- Your car’s web browser may be on the road to cyber ruinby Thomas Claburn on December 18, 2025 at 8:13 pm
Study finds built-in browsers across gadgets often ship years out of date Web browsers for desktop and mobile devices tend to receive regular security updates, but that often isn’t the case for those that reside within game consoles, televisions, e-readers, cars, and other devices. These outdated, embedded browsers can leave you open to phishing and other security vulnerabilities.…
- Crypto crooks co-opt stolen AWS creds to mine coinsby Jessica Lyons on December 18, 2025 at 6:53 pm
‘Within 10 minutes of gaining initial access, crypto miners were operational’ Your AWS account could be quietly running someone else’s cryptominer. Cryptocurrency thieves are using stolen Amazon account credentials to mine for coins at the expense of AWS customers, abusing their Elastic Container Service (ECS) and their Elastic Compute Cloud (EC2) resources, in an ongoing operation that started on November 2.…
- Kim’s crypto thieving reached a record $2B in 2025by Connor Jones on December 18, 2025 at 5:47 pm
ByBit attack doing some seriously heavy lifting North Korea’s yearly cryptocurrency thefts have accelerated, with Kim’s state-backed cybercriminals plundering just over $2 billion worth of tokens in 2025.…
- Another bad week for SonicWall as SMA 1000 zero-day under active exploitby Carly Page on December 18, 2025 at 2:34 pm
Flaw in remote-access appliance lets attackers chain bugs for root-level takeover SonicWall has warned customers of a zero-day flaw in its SMA 1000 remote-access appliance that’s being actively exploited, potentially allowing attackers to escalate privileges and take over boxes.…
- FBI dismantles alleged $70M crypto laundering operationby Carly Page on December 18, 2025 at 1:52 pm
Justice Department claims unlicensed exchange funneled ransomware profits US feds have dismantled a crypto laundering service that they say helped cybercrooks wash tens of millions of dollars in dirty digital cash, seizing its servers and unsealing charges against an alleged Russian operator.…
- NHS tech supplier probes cyberattack on internal systemsby Connor Jones on December 18, 2025 at 1:02 pm
Around 2,000 GP practices use its products Updated An NHS tech supplier is investigating a cyberattack that affected its systems in the early hours of Sunday.…
- React2Shell exploitation spreads as Microsoft counts hundreds of hacked machinesby Carly Page on December 18, 2025 at 11:42 am
Security boffins warn flaw is now being used for ransomware attacks against live networks Microsoft says attackers have already compromised “several hundred machines across a diverse set of organizations” via the React2Shell flaw, using the access to execute code, deploy malware, and, in some cases, deliver ransomware.…
- DVSA’s clapped-out booking system gets bot slapped as new boss rides inby SA Mathieson on December 18, 2025 at 9:38 am
18-year-old platform crumbles under 94M daily requests while resellers flog £62 tests for £500 The UK’s Driver and Vehicle Standards Agency (DVSA) has appointed a new chief exec to tackle spiraling waits for practical driving tests with bots overrunning its aging booking system.…
- UK surveillance law still full of holes, watchdog warnsby Connor Jones on December 18, 2025 at 9:15 am
Investigatory Powers Commissioner says reforms have failed to close oversight gaps The UK’s Investigatory Powers Act 2016 (IPA) has several regulatory gaps that must be plugged in future legislative reforms, according to Investigatory Powers Commissioner (IPC) Sir Brian Leveson.…
- Attacks pummeling Cisco AsyncOS 0-day since late Novemberby Jessica Lyons on December 17, 2025 at 10:51 pm
No timeline for a patch Suspected Chinese-government-linked threat actors have been battering a maximum-severity Cisco AsyncOS zero-day vulnerability in some Secure Email Gateway (SEG) and Secure Email and Web Manager (SEWM) appliances for nearly a month, and there’s no timeline for a fix.…
- CEO spills the Tea about massive token farming campaignsby Jessica Lyons on December 17, 2025 at 10:29 pm
Plus: automated SBOMs, $250,000 bounties ahead interview No good idea – like rewarding open source software developers and maintainers for their contributions – goes unabused by cybercriminals, and this was the case with the Tea Protocol and two token farming campaigns.…
- Blockchain company Nomad to repay users under FTC deal after $186M cyberattackby Connor Jones on December 17, 2025 at 4:03 pm
Regulator makes various additional demands over alleged cybersecurity failings In proposing a settlement agreement, the Federal Trade Commission (FTC) says that Illusory Systems must repay users funds lost in a 2022 cyberattack.…
- PwC on securing AI: building trust, compliance and confidence at scaleby David Gordon on December 17, 2025 at 4:01 pm
Buckle up to innovate at speed, says PwC Sponsored Post As AI spreads across the enterprise, so too do the security and compliance risks. Regulations are evolving, risk postures are shifting, and organizations must find a way to innovate responsibly without slowing down.…
- NATO’s battle for cloud sovereignty: Speed is existentialby Joe Fay on December 17, 2025 at 2:54 pm
Build a digital backbone faster than adversaries can evolve or lose the information war NATO is in an existential race to develop sovereign cloud-based technologies to underpin its mission, the alliance’s Assistant Secretary General for Cyber and Digital Transformation told an audience at the Royal United Services Institute (RUSI) last week.…
- Microsoft security update breaks MSMQ on older Win systemsby Richard Speed on December 17, 2025 at 1:52 pm
Folder permission changes cause queue failures and misleading error messages, no real fix yet Microsoft has good news for administrators: while some organizations now pay for security updates on older Windows versions, the inconsistent quality remains free.…
- England keeping pen and paper exams despite limited digital expansionby SA Mathieson on December 17, 2025 at 10:15 am
Regulator proposes strict limits on screen-based testing, cites infrastructure concerns and lack of evidence for benefits Most students taking school and college GCSE, A-level, and AS-level exams in England will continue to use pen and paper, according to proposals from the sector’s regulator for a very limited expansion of screen-based assessments.…
- China’s Ink Dragon hides out in European government networksby Jessica Lyons on December 16, 2025 at 11:19 pm
Misconfigured servers are in, 0-days out Chinese espionage crew Ink Dragon has expanded its snooping activities into European government networks, using compromised servers to create illicit relay nodes for future operations.…
- Analytics provider: We didn’t expose smut site data to crimsby Jessica Lyons on December 16, 2025 at 9:48 pm
An employee of the adult site could be responsible. Analytics vendor Mixpanel says it is not the source of data stolen from Pornhub and says the info was last accessed by an employee of the adult site.…
- Browser ‘privacy’ extensions have eye on your AI, log all your chatsby Thomas Claburn on December 16, 2025 at 9:03 pm
More than 8 million people have installed extensions that eavesdrop on chatbot interactions Ad blockers and VPNs are supposed to protect your privacy, but four popular browser extensions have been doing just the opposite. According to research from Koi Security, these pernicious plug-ins have been harvesting the text of chatbot conversations from more than 8 million people and sending them back to the developers.…
- SantaStealer stuffs credentials, crypto wallets into a brand new bagby Jessica Lyons on December 16, 2025 at 6:58 pm
All I want for Christmas … is all of your data A new, modular infostealer called SantaStealer, advertised on Telegram with a basic tier priced at $175 per month, promises to make criminals’ Christmas dreams come true. It boasts that it can run “fully undetected” even on systems with the “strictest AntiVirus” and those belonging to governments, financial institutions, and other prime targets.…
- From pr0n to playlists and paperclips, trio of breaches spills data of millionsby Carly Page on December 16, 2025 at 12:33 pm
Adult site, streaming platform, and Japanese retailer expose user info, but not credentials Three very different companies have now confirmed data breaches affecting millions of users – each insisting the damage stopped well short of passwords and payment details.…
- MI6 chief: We’ll be as fluent in Python as we are in Russianby SA Mathieson on December 16, 2025 at 11:45 am
New spy boss says officers must master code alongside tradecraft as agency navigates ‘space between peace and war’ New MI6 chief Blaise Metreweli outlined her vision for technology-augmented intelligence gathering in her first public speech on December 15, warning that the UK operates “in a space between peace and war.”…
- PwC on using AI to turn cybersecurity risk into competitive advantageby David Gordon on December 16, 2025 at 5:50 am
PwC supports clients across the full cyber lifecycle Sponsored Post Managing cybersecurity risk has never been simple, but in today’s threat landscape it can also become a source of strength. PwC believes that AI is now central to that transformation, helping organizations not just react faster to attacks, but evolve their defences with greater confidence.…
- No, SoundCloud hasn’t started tuning out VPNs. It’s mopping up after a cyberattackby Simon Sharwood on December 16, 2025 at 5:20 am
Bum note for 20 percent of users whose data leaked Music hosting and streaming service SoundCloud has admitted it suffered a cyberattack.…
- Amazon security boss blames Russia’s GRU for years-long energy-sector hacksby Jessica Lyons on December 15, 2025 at 11:34 pm
‘Sustained focus on Western critical infrastructure’ Russia’s Main Intelligence Directorate (GRU) is behind a years-long campaign targeting energy, telecommunications, and tech providers, stealing credentials and compromising misconfigured devices hosted on AWS to give the Kremlin’s snoops persistent access to sensitive networks, according to Amazon’s security boss.…
- China, Iran are having a field day with React2Shell, Google warnsby Jessica Lyons on December 15, 2025 at 5:53 pm
Who hasn’t exploited this max-severity flaw? At least five more Chinese spy crews, Iran-linked goons, and financially motivated criminals are now attacking React2Shell, a maximum-severity flaw in the widely used React JavaScript library, according to Google.…
- Delay to European Central Bank messaging project cost the Bank of England £23Mby Lindsay Clark on December 15, 2025 at 12:50 pm
Watchdog links schedule change to replanning of UK payments system overhaul The European Central Bank’s (ECB) decision to delay its move to a new messaging standard in 2022 ended up costing the Bank of England £23 million as it was forced to adjust migration to a new settlement system to avoid compounding risks.…
- JLR: Payroll data stolen in cybercrime that shook UK economyby Carly Page on December 15, 2025 at 12:08 pm
Automaker admits raid that crippled its factories in August led to the theft of sensitive info Jaguar Land Rover (JLR) has reportedly told staff the cyber raid that crippled its operations in August didn’t just bring production to a screeching halt – it also walked off with the personal payroll data of thousands of employees.…




