OnePlus leaves researchers on read over Android bug that exposes texts Rapid7 warns flaw could let any app peek at your SMS, but smartphone vendor won't pick up Security researchers report that OnePlus smartphone users remain vulnerable to a critical bug that allows any application to read SMS and MMS data β€” a flaw that has persisted since late 2021.… #theregister #IT
MX Linux 25 reaches beta testing – complete with systemd Fancy a taste? The version based on Debian 'Trixie' is nearly ready, but not all the changes may be entirely welcome The new Debian-13 version of MX Linux, version 25, is looking very close to ready for release. A big change may divide its audience, though.… #theregister #IT
SIM city: Feds say 100,000-card farms could have killed cell towers in NYC Secret Service seizes 300-server network allegedly tied to nation-state hackers The US Secret Service has dismantled a network of SIM farms in and around New York City it claims was behind multiple incidents targeting senior government officials and had enough power to disrupt entire cellular networks.… #theregister #IT
Kaspersky: RevengeHotels checks back in with AI-coded malware Old hotel scam gets an AI facelift, leaving travellers’ card details even more at risk Kaspersky has raised the alarm over the resurgence of hotel-hacking outfit "RevengeHotels," which it claims is now using artificial intelligence to supercharge its scams.… #theregister #IT
OpenSSF warns that open source infrastructure doesn't run on thoughts and prayers Foundations say billions of downloads rely on registries running on fumes – and someone's gotta pay the bills The Open Source Security Foundation (OpenSSF) has had enough of being the unpaid janitor of the world's software supply chain.… #theregister #IT
GitHub moves to tighten npm security amid phishing, malware plague Hundreds of compromised packages pulled as registry shifts to 2FA and trusted publishing GitHub, which owns the npm registry for JavaScript packages, says it is tightening security in response to recent attacks.… #theregister #IT
Oracle gets to store US users' TikTok data, says Trump President to announce details on Big Red’s storage and security deal for Chinese social media phenomenon later this week The White House has promised that all US user data on TikTok will be stored on Oracle servers in the United States, according to a deal to be announced later this week.… #theregister #IT
Workers fear for their jobs as JLR's latest shutdown extended With no idea when engines restart, families gear down on spending ahead of Christmas Jaguar Land Rover is extending the shutdown of its production plants another week in a move that experts say could cost the business in the multiple billions.… #theregister #IT
Slow Wi-Fi? Add houseplants to the list of suspects Not as bad as other interference, but maybe it's time for a wired connection Houseplants could be slowing down your Wi-Fi, according to Broadband Genie, which reckons surfers can increase broadband speeds by almost 40 percent just by moving their router away from any greenery.… #theregister #IT
Suspected Iran-backed attackers targeting European aerospace sector with novel malware Instead of job offers, victims get MiniJunk backdoor and MiniBrowse stealer Suspected Iranian government-backed online attackers have expanded their European cyber ops with fake job portals and new malware targeting organizations in the defense, manufacturing, telecommunications, and aviation se… #theregister #IT