The Register, Security (discovery feed)
theregister-security-feed · C · candidate
https://www.theregister.com/security/
Added 2026-10-06: S1 candidate; the dated Atom feed (`feed https://www.theregister.com/security/headlines.atom 30`) surfaced the Atlassian advisory hours ahead of any national-CERT relay and quotes watchTowr and VulnCheck primaries. Discovery lead only, never a terminal source (reliability C); article bodies read via `url` (raw HTML, paragraphs), `extract` returned only navigation boilerplate for the Atlassian article.
Cited in 31 entries
Citation cadence
Citation days per ISO week (23 weeks of coverage span, total 27).
- CVE-2026-21589, Atlassian Data Center: unauthenticated arbitrary file access in every version of eight self-managed products, patch or take them off the internet (CVSS 4.0 9.3)2026-10-06
- An internal OpenAI agent reached non-public files on an Australian government Medicare statistics portal that Canberra called hacked; archived portal code suggests the portal served them to any visitor2026-09-24
- Manchester Airports Group confirms a breach touching roughly 8.7 million customers across Manchester, Stansted and East Midlands, car-park, lounge and airport-WiFi sign-up data taken; FulcrumSec later claims credit and a client-side API-credential access vector2026-08-28
- Akira blinds EDR by rebooting a victim host into Safe Mode with Networking, the operator's first observed use of the technique, and the stripped-down boot starved its own encryptor2026-08-17
- France's tax authority says it cut the intruders' accounts in June and July and found no data theft; it took the criminal's sale listing two months later to establish that 678,000 records had already gone2026-08-15
- A lone actor used a jailbroken Gemini CLI to autonomously rebuild and redeploy C2 infrastructure in six minutes ("Patriot Bait")2026-07-14
- Progress orders ShareFile Storage Zone Controller shutdown over a 'credible external threat'; the cause is a path-traversal flaw, fixed in 5.12.5 and 6.0.22026-07-13
- Medtronic notifies ~9 million people of a ShinyHunters-claimed corporate-IT breach, 2.5 months after containment2026-07-03
- CVE-2026-12957, Amazon Q Developer auto-loaded workspace MCP configs, enabling repo-planted code execution and AWS credential theft (Wiz)2026-06-27
- Two Scattered Spider members plead guilty over the 2024 Transport for London intrusion2026-06-23
- Texas Parks & Wildlife: 3.08M licence holders exposed via an unnamed third-party vendor, with a public-vs-AG-filing SSN contradiction2026-06-21
- CVE-2026-20262, Cisco Catalyst SD-WAN Manager: authenticated arbitrary file write to root RCE (CISA KEV)2026-06-16
- Cisco Catalyst SD-WAN Manager CVE-2026-20262: authenticated arbitrary file write to root RCE2026-06-16
- Novo Nordisk discloses theft of clinical-trial and healthcare-professional data2026-06-13
- "GreatXML": unpatched BitLocker bypass via crafted XML on the recovery partition, PoC public, practical severity contested2026-06-12
- ShinyHunters Oracle PeopleSoft campaign: gadget-chain access, SSH default-credential lateral movement, mass exfiltration2026-06-11
- France's Tchap government messenger breached via account takeover, 73,467 civil servants' metadata scraped, CNIL notified2026-06-10
- Oxford University CareerConnect (Group GTI) breach exposes students at multiple UK universities2026-06-09
- California AG sues former 23andMe (Chrome Holding Co.) over the 2023 genetic-data breach, bulk-enumeration coding error plus absent credential-stuffing defences2026-05-31
- Carnival Corporation confirms 5.99 M-record ShinyHunters breach, passport + driver's-licence numbers exposed across four cruise brands2026-05-29
- FBI PSA260521, Kali365 OAuth device-code PhaaS bypasses M365 MFA without credential capture2026-05-23
- CVE-2026-20223, Cisco Secure Workload: CVSS 10.0 zero-auth REST API grants Site Admin privileges across all tenants, no workaround2026-05-22
- Drupal core "highly critical" pre-patch warning, unauthenticated, zero-complexity, patch window today 17:00–21:00 UTC2026-05-20
- Grafana Labs CoinbaseCartel breach; victim confirms source-code-only theft, no customer data, ransom rejected2026-05-19
- Windows BitLocker "YellowKey" and CTFMON "GreenPlasma" zero-days: public PoC, no patch, TPM-only BitLocker bypassed2026-05-15
- Microsoft MDASH, multi-model agentic vulnerability-discovery harness finds 16 Windows CVEs in network-stack kernel components2026-05-13
- Foxconn confirms Nitrogen ransomware crippled North-American manufacturing sites; 8 TB / 11M files claimed2026-05-13
- BWH Hotels (Best Western, WorldHotels, Sure Hotels), 181-day unauthorised access to a guest-reservation web application, six EU brands in scope2026-05-13
- ICO fines South Staffordshire Water £963,900, water-sector OES with partial SIEM coverage; Cl0p attribution and ZeroLogon kill-chain detail sourced to The Record2026-05-12
- GTIG AI Threat Tracker (May 2026): First Confirmed AI-Generated Zero-Day Exploit ITW and the Behavioural Class of AI-Augmented Malware2026-05-12
- Instructure/Canvas extortion: 330 institutions across six countries; May 12 extortion deadline; 44 Dutch institutions confirmed2026-05-08