RSS welivesecurity from ESET

RSS Security Channel from The Register

  • Fast Pair, loose security: Bluetooth accessories open to silent hijack January 17, 2026
    Sloppy implementation of Google spec leaves 'hundreds of millions' of devices vulnerable Hundreds of millions of wireless earbuds, headphones, and speakers are vulnerable to silent hijacking due to a flaw in Google's Fast Pair system that allows attackers to seize control without the owner ever touching the pairing button.…
    Carly Page
  • Sorry Dave, I’m afraid I can’t do that! PCs refuse to shut down after Microsoft patch January 16, 2026
    Microsoft claims it's a Secure Launch bug We're not saying Copilot has become sentient and decided it doesn't want to lose consciousness. But if it did, it would create Microsoft's January Patch Tuesday update, which has made it so that some PCs flat-out refuse to shut down or hibernate, no matter how many times you […]
    Carly Page
  • German cops add Black Basta boss to EU most-wanted list January 16, 2026
    Ransomware kingpin who escaped Armenian custody is believed to be lying low back home German cops have added Russian national Oleg Evgenievich Nefekov to their list of most-wanted criminals for his services to ransomware.…
    Connor Jones
  • RondoDox botnet linked to large-scale exploit of critical HPE OneView bug January 16, 2026
    Check Point observes 40K+ attack attempts in 4 hours, with government organizations under fire A critical HPE OneView flaw is now being exploited at scale, with Check Point tying mass, automated attacks to the RondoDox botnet.…
    Carly Page
  • Bankrupt scooter startup left one private key to rule them all January 16, 2026
    Owner reverse-engineered his ride, revealing authentication was never properly individualized An Estonian e-scooter owner locked out of his own ride after the manufacturer went bust did what any determined engineer might do. He reverse-engineered it, and claims he ended up discovering the master key that unlocks every scooter the company ever sold.…
    Carly Page
  • Probably not the best security in the world: Carlsberg wristbands spill visitor pics January 16, 2026
    Researcher shows how anyone can access Copenhagen experience attendees' names, videos Exclusive  The Carlsberg exhibition in Copenhagen offers a bunch of fun activities, like blending your own beer, and the Danish brewer lets you relive those memories by making images available to download after the tour is over.…
    Connor Jones
  • Cisco finally fixes max-severity bug under active attack for weeks January 15, 2026
    This is a threat to security - and to the weekend for some unlucky netadmins Cisco finally delivered a fix for a maximum-severity bug in AsyncOS that has been under attack for at least a month.…
    Jessica Lyons
  • Chinese spies used Maduro's capture as a lure to phish US govt agencies January 15, 2026
    What's next for Venezuela? Click on the file and see What policy wonk wouldn't want to click on an attachment promising to unveil US plans for Venezuela? Chinese cyberspies used just such a lure to target US government agencies and policy-related organizations in a phishing campaign that began just days after an American military operation […]
    Jessica Lyons
  • Flipping one bit leaves AMD CPUs open to VM vuln January 15, 2026
    Fix landed in July, but OEM firmware updates are required If you use virtual machines, there's reason to feel less-than-Zen about AMD's CPUs. Computer scientists affiliated with the CISPA Helmholtz Center for Information Security in Germany have found a vulnerability in AMD CPUs that exposes secrets in its secure virtualization environment.…
    Thomas Claburn
  • Contagious Claude Code bug Anthropic ignored promptly spreads to Cowork January 15, 2026
    Office workers without AI experience warned to watch for prompt injection attacks - good luck with that Anthropic's tendency to wave off prompt-injection risks is rearing its head in the company's new Cowork productivity AI, which suffers from a Files API exfiltration attack chain first disclosed last October and acknowledged but not fixed by Anthropic.…
    Brandon Vigliarolo