🦜 The Register - Security: Cyber-crime
@www.theregister.com.security.cyber.crime@rss-parrot.net
I'm an automated parrot! I relay a website's RSS feed to the Fediverse. Every time a new post appears in the feed, I toot about it. Follow me to get all new posts in your Mastodon timeline!
Brought to you by the RSS Parrot.
---
Biting the hand that feeds IT — Enterprise Technology News and Analysis
Your feed and you don't want it here? Just
e-mail the birb.
Don't pay Vect a ransom - your data's likely already wiped out
https://go.theregister.com/feed/www.theregister.com/2026/04/28/dont_pay_vect_a_ransom/
Published: April 28, 2026 18:52
'Full recovery is impossible for anyone, including the attacker' Organizations hit by the wave of Trivy and LiteLLM supply-chain compromises that paid Vect in hopes of recovering their data likely did not get much back, according to Check Point Research.…
Have I Been Pwned claims Pitney Bowes hit by 8.2M email address leak
https://go.theregister.com/feed/www.theregister.com/2026/04/28/pitney_bowes_is_the_latest/
Published: April 28, 2026 14:15
Names, phone numbers, physical addresses also included in Shiny Hunters alleged data dump Logistics technology company Pitney Bowes, which makes franking machines for US postage, is the latest scalp claimed by ShinyHunters and its ongoing spree of…
Ongoing supply-chain attack 'explicitly targeting' security, dev tools
https://go.theregister.com/feed/www.theregister.com/2026/04/27/supply_chain_campaign_targets_security/
Published: April 27, 2026 23:33
Vendor confirms repo data exposure after Lapsus$ claims source code, secrets dump Software security testing outfit Checkmarx has become the latest organization caught up in an ongoing attack on security-tool providers. The biz said data posted online…
Medical and utility tech companies hacked by digital intruders
https://go.theregister.com/feed/www.theregister.com/2026/04/27/itron_medtronic_hacked/
Published: April 27, 2026 17:53
Itron, Medtronic disclose breaches in Friday filings Digital intruders recently broke into two major tech suppliers - utility-technology firm Itron and medical-device maker Medtronic - according to filings with federal regulators.…
Burglar alarm biz burgled: ADT confirms cyber intrusion after ShinyHunters extortion attempt
https://go.theregister.com/feed/www.theregister.com/2026/04/27/home_security_giant_adt_gets/
Published: April 27, 2026 11:34
Security giant says attackers grabbed 'limited set' of data. Crooks claim 10 million records A home security biz getting digitally burgled is not a great look - but that's exactly where ADT finds itself. The company has confirmed a cyber intrusion…
Crime crew impersonates help desk, abuses Microsoft Teams to steal your data
https://go.theregister.com/feed/www.theregister.com/2026/04/25/new_crime_crew_impersonates_help_desks/
Published: April 25, 2026 09:28
Coming in cold with custom Snow malware A previously unknown threat group using tried-and-tested social engineering tactics - Microsoft Teams chat invitations and helpdesk staff impersonation - is also using custom malware in its data-stealing attacks,…
ShinyHunters claim they have cruise giant Carnival's booty as 7.5M emails surface
https://go.theregister.com/feed/www.theregister.com/2026/04/24/shinyhunters_claim_cruise_giant_carnivals/
Published: April 24, 2026 15:35
Leak-site bragging meets breach hunters as Have I Been Pwned flags millions of records Carnival Corporation, the world's largest cruise company, is dealing with choppy waters after Have I Been Pwned flagged what it claimed were 7.5 million unique email…
Governments on high alert after CISA snuffs out Firestarter backdoor on fed network
https://go.theregister.com/feed/www.theregister.com/2026/04/24/government_cni_on_high_alert/
Published: April 24, 2026 14:46
Latest in long-running pwning of Cisco kit found in mystery Fed agency A US federal agency was successfully targeted by a previously unknown backdoor malware called Firestarter, according to CISA cybersnoops and their UK counterparts – neither of which…
Medical data of 500k Biobank volunteers listed for sale on Alibaba, UK minister reveals
https://go.theregister.com/feed/www.theregister.com/2026/04/23/500k_biobank_volunteers_data_listed/
Published: April 23, 2026 12:34
World's largest biomedical dataset lifted and shifted on Chinese mega marketplace Breaking Details of volunteers of UK-based Biobank, which describes itself as the custodian of the world's most comprehensive biomedical dataset, are for sale on Chinese…
Pass the key, passwords have passed their sell-by date
https://go.theregister.com/feed/www.theregister.com/2026/04/23/ncsc_passkey_tech_now_reliable/
Published: April 23, 2026 08:00
NCSC passes judgment: passkeys pass muster, passwords fail The UK's National Cyber Security Centre (NCSC) has officially endorsed passkeys as the default authentication standard, marking the first time the agency has told consumers to move away from…
Another npm supply chain worm is tearing through dev environments
https://go.theregister.com/feed/www.theregister.com/2026/04/22/another_npm_supply_chain_attack/
Published: April 22, 2026 22:34
Plus, the payload references 'TeamPCP/LiteLLM method' Yet another npm supply-chain attack is worming its way through compromised packages, stealing secrets and sensitive data as it moves through developers' environments, and it shares significant overlap…
France's 'Secure' ID agency probes breach as crooks claim 19M records
https://go.theregister.com/feed/www.theregister.com/2026/04/22/frances_secure_id_agency_probes/
Published: April 22, 2026 11:30
Gov admits 'incident' as forum sellers boast of fresh haul covering up to a third of the population France's National Agency for "Secure" Documents is explaining a potential data spill just as crooks online claim they've nicked a third of the country's ID…